Tuesday, June 28, 2016

Ransomware a Digital Era weapon, a high Revenue business!!!

The world today is full of unlimited business opportunities. We all operate in the digital era to perform business operations (by Connecting people, enterprises, Smart Cities, systems, LOT, Utilities, Smart Grids/Meters, Big Data and Analytics and SMAC across the globe). We follow standard operating procedure defined during Stone Age without giving due diligence to the upcoming threat landscape.

This post is informative in nature and will help people who think cyber-attacks are not meant for them or they will never get affected due to either nature of their business or scale of their business. Be prepared, you can be the easy Target!!!

I would like to share a true incident happened in a Non-IT organization which resulted in big havoc and made complete operation at a stand still for few days. Million dollar loss!!!

It was a normal day when I received a call from my friend requesting some help since I understand security operations. I casually inquired the reason behind; however, I felt he was little hesitating. During the conversation, he mentioned that his customer is facing major issue due to malware attack and he requested my help to rescue. On his request, I agreed to socialize with the customer. Let me narrate the complete conversation-
During the conversation, I came to know that he is heading the IT operation and seems to be in a deep problem. Initially, he was hesitating in sharing the issue due to company reputation and market share. However, based on my assurance he stated to me that the complete IT operation is stopped due to malware attack. With a deep breath, I asked him more detail on the behavior of malware and the issue so that I can suggest mitigation plan. According to him……
  • The organization is Touching lives of millions across India, Asia, the Middle East, Europe, Africa and America. Huge Network!!!
  • The malware has encrypted all the business operation devices and asking for money to decrypt the file system.
  • The files are encrypted with.AAA extension.
  • Not sure how many systems are infected and will infect
  • Antivirus solution is not protecting… Antivirus claim to be zero-day exploits
  • A local vendor who is supporting the operation is not a commitment to handle security incident.Technical competency issue with local vendor
  • We can’t align with CERT-In (Indian - Computer Emergency Response Team) to report and to take their concurrence and advice due to company reputation.  

With a deep breath, I understood the complete issue. It was an “Encrypted Ransomware” attack. A Highly-Profitable Evolving Threat!!!
Okay, let me brief you exactly how it functions.

Ransomware, as terms, says it’s related to ransom; however in the current circumstance, it’s related to “Digital Ransom”. In the current context, the attacker has encrypted the digital information and asking Ransom money to rescue/decrypt the data so that it can be used for the business operation. It’s a big call which customer has to make, considering

  • How to make business operational with no impact on business and Market Share
  • The impact of the encrypted file. Data Restoration, if we plan to delete everything and restore from backup. Which day backup to refer, since no clarity if the backup itself is infected. 
  • How many systems affected due to self-replicating behavior
  • Do we have any controls to identify the Source of the attack  
  • When it was infected since much malicious code remains undetected due to APT behaviors.
  • What would be the impact on company reputation, if the Ransom is paid
  • How we can safeguard considering attacker might have key to our network
  • How to mitigate the same incident again 


Before Business takes a call on the above alarming question, let’s understand little more on how it works and how it’s impacting the users across the Globe.
  
Ransomware can exhibit worm-like behavior and can remain undetected. The ransom leverages removable and network drives to propagate itself and affect more users. There are many forms of Ransomware someone of which has destructive nature i.e. they are designed with automated counter, once reached the threshold it will start deleting the files. If you restart the computer or try to stop its services, it becomes more disruptive and may delete 1000 of files. Ransomware Boss (In IT Terms, can be referred as a Program Head) will establish the complete program like a project J.The leader (In IT Terms can be referred as a Technical lead) is recruited from 10 to 15 affiliates that supported him in spreading the ransomware via:
  1. Botnet installs
  2. Email and social media phishing campaigns
  3. Compromised dedicated servers
  4. File-sharing websites


Let’s understand the market analysis so that we can Say “No to Digital Threat in cross connected ecosystem”  

Facts
Revenue Business from Ransomware
  • Half of the users can’t accurately identify ransomware
  •  Half of the victims are willing to pay up to $500 to recover encrypted data. This means according to the graph; there are nearly 200K infected users. If half of them pay 500 USD, it makes a total of 50,000,000 USD!
  • Personal documents rank first among user priorities.
  • UK consumers would pay most to retrieve files.
  • US users are the main target for ransomware.
  •  Indian Users are also targeted; however never reported.
  • One of the most interesting aspects of ransomware campaigns is that they could also be very profitable for small gangs without specific skills.
  • A ransomware-as-a-service campaign operated by a Russian gang since December 2015
  • The gang requested the victims a payment of a $300 fee to rescue to encrypted files, the communications with the victims are handled directly by the boss.
  • 93% of phishing emails are now ransomware




Growth of Encrypted Ransomware Q1 2016



The best preparation for tomorrow is doing your best today. In my next post, I will be guiding on developing a holistic approach on how to battle with ransomware proactively to avoid massive destruction along with Mitigation approach. Till then stay safe!!!

Tuesday, October 27, 2015

Cyber Crime a Smart City Killer. Closed-Circuit Security Cameras a Digital War Weapon

Smart City: “A city that uses technology to automate and improve city services, making citizens’ lives better.” The definition looks very interesting however as said, All good things are difficult to achieve, and bad things are very easy to get a parcel. With regards to smart city, Cyber Attacks plays a major role and is the main contributor which can make complete system at halt

Smart City comprises of below critical functions-



  1. Traffic Control Systems
  2. Smart Street Lighting
  3. City Management Systems
  4. Sensors
  5. Public Data
  6. Mobile Applications
  7. Cloud and SaaS Solutions
  8. Smart Grid
  9. Public Transportation
  10. Cameras
  11. Social Media
  12. Location-based Services
  13. Etc.

To effectively run the Smart City operation, a complete governance framework needs to be setup which requires monitoring.

Let's takes a simple scenario of point no. 10 which is a very elementary component of smart city solution; however, plays a very vital role. Closed-circuit security cameras are supposed to make you safer to run the city operation, but there are many ways to turn them into weapons like sabotage manually or using malware. Researchers have discovered code that turned about 900 Linux-based CCTV cameras into a botnet, which promptly bombarded an unnamed "large cloud service" that serves millions of people. The intruders compromised cameras from multiple brands, all of which had lax out-of-the-box security -- in some cases, they'd been hacked by more than one person.
A botnet is a collection of compromised computers often referred to as “zombies” infected with malware that allows an attacker to control them. Botnet owners or “herders” are able to control the machines in their botnet by means of a covert channel such as IRC (Internet Relay Chat), issuing commands to perform malicious activities such as distributed denial-of-service (DDoS) attacks, the sending of spam mail, and information theft

The botnet conducted a "run of the mill" denial of service attack, and it would be relatively easy to thwart the attackers with a bit of caution. However, it underscores the potential dangers of security cameras. There are millions of connected cams worldwide, many of which likely weren't installed properly -- and it'd be trivial to use those cameras to spy on people. Until companies either ship more secure cameras or tell their customers how to protect themselves, these surveillance systems will likely represent an ongoing risk.

Let me show you a small demo; how a Closed-circuit security camera can be hacked easily with simple steps.Please note, I am not encouraging people to hack others system; however objective is to educate about consequences if your camera is not secured. 

Consequences could be more devastating like a Terrorist attack on sensitive government functions as mentioned above, Bank operation to sabotage and to gain financial benefit ( what if CCTV camera of ATM or bank is hijacked to perform robbery), what if your privacy is made public by controlling your personal or public cameras. What if someone is controlling the operation of Smart Grid or monitoring Traffic Control Systems for any illegal activity. The complete surveillance will go for a toss. We should give equal importance to physical security as well as digital aspect(which we are talking about). Placing a camera is secure environment is very important for digital operation.

To test this scenario, I quickly evaluated my public IP address and then I did scanning to look for a system which has a camera installed by giving an IP range. As part of this process, I selected the web detect option. Web detect is used when we want to know small details about the devices that are connected to the internet. For example any router name or the CCTV camera name or the model number.

So you got the complete result of your scan operation -



The highlighted part shows the system with Camera installed. There are few parameters by which you can recognize your CCTV camera. 
  • DVRDVS-Webs – CCTV camera
  • Webs – CCTV camera
  • Hikvision-Webs — CCTV camera
  • iBall-Baton — CCTV camera
  • uc-httpd 1.0.0 — CCTV camera


   And by simply browsing the IP address, I am able to get the login page of the camera system.


Now, I know the make of the device i.e. Hikvision Digital Technology Co. Majority of cameras is deployed by engineers who doesn't understand the consequences of using the default password. Here you go with the password. Most of the CCTV cams and router has the default password in it so they can easily be hacked and the hacker can inject botnet or zombies to execute the digital war.


And finally, you are in!!!. 



This article is only for educational purposes and encourages administrator to secure the camera interfaces using best practices. In my subsequent article, I will show you how to secure your camera's for better future operations from Cyber Crime. Till then Happy Reading.....

Monday, November 10, 2014

Are you a Weakest Link of your Business-5 Common cause

Organization scramble to achieve high business growth often overlooked the underlying processes which are the core of any business operation. A manual process to handle employee separation process lead devastating circumstances. Most organization take an almost couple of weeks to manage separation process and at times it become unnoticeable for years. 
"Are you a Weakest Link of your Business"

There have been cases of data loss, where employees were part of such acts during the transition to a new job. A report by “Bnet” shows that 45 percent of employees take data when they change jobs. Such is the case with a former HP employee, who had allegedly sent copies of IBM confidential documents to his Vice President at HP. Prior to joining HP, he was employed by IBM and had access to this information.

For most organization the generalize causes for data breach are-
  • Identity & Access Management (IAM) solution not correctly in place or may not be designed effectively-It is often observed that enterprise doesn't develop correct boundaries for IAM. The most important question every CISO or CIO concern about is optimization and efficiency around processes with minimal security incident (to make close to zero). This often leads to comparison with peers on-
           -      How we are doing as an organization?
           -      What is the next step for building a secure Environment using IAM 
                  Infrastructure?
           -      How to develop IAM maturity model 
  • Data Loss Prevention system is missing or may not be developed correctly.
  • Data Analytics not mature to address current security landscape with proper escalation mechanism.
  • Inadequate testing to capture all the scenarios (happy & unhappy) while developing the system.
  • The vendor is not equipped with SME and domain expertise to understand Technology trends. Scalable enterprise visibility to provide intelligent threat analytics capability.
 Best practices to energize enterprise maturity to overcome data beach. 
  • A rapid incident detection and response framework with relevant investment from enterprise to mark as a continue process improvement model.
  • To build flexible and powerful automation capabilities to adopt speed, agility, and scalability.
    • Developing a Strong Enterprise processes Automation using Identity & Access Management (IAM) solution. Separation Process should be in place to handle employee resignation scenario and removing access rights to critical systems during Employee Notice period.
    • Missing Data Loss Prevention system-A Proper implementation of DLP would have marked this data as sensitive and rated it highly critical. Common exit points of this type of data breach are corporate email, webmail, FTP, removable drives, and printing. At any of these exit points, DLP would have flagged this activity. Let's explore the effectiveness of DLP in the enterprise-There has been misleading information of DLP being able to identify 370 plus file formats. File type identification does not translate into content inspection. It is roughly about 180 file types that this technology can interpret and inspect the contents. In order for DLP to do its job effectively, content inspection is important. Customers tend to get sold on the sheer number of 370 when in fact, DLP is equipped to tear down the file on less than half of them. Implement continues enterprise data fingerprinting to minimize inside data breach.
    • Bi-Direction integration with existing security solution like SIEM, IAM, DLP and developing an intelligent threat BIG Data analytics capability to give complete enterprise visibility.
  • Enforcing Periodic System and process review 
  • Enterprise needs to align with vendors who understand the Subject and can translate business processes keeping domain and business objective in mind.

Thursday, March 6, 2014

Sound as virus!!! Can a computer virus communicate Via ultrasound signals?

One of the go-to strategies for securing a computer network when a machine is infected with malware is to remove that machine from the network. This effectively prevents the malware from spreading to other devices. This Technique is called as Air-Gapping which isolate the system by introducing air gap by removing Network Connectivity.But still, Hacker Can Infect your machine if it's not connected to Network using “Air-Gap Malware”.

How does it work and how it came into existence?

Research has shown that the sounds of a dot matrix printer can be used to reverse-engineer the content being printed. In effect, this means that any person sitting in the reception area of the doctor can record the sound of the printer and can reconstruct the printed text.
Air-gap malware is that which is able to jump the air-gap by "translating" malicious computer code into high-frequency sound, then transmitting that sound to infect nearby computers.

Computer data can't travel over the air in its raw form, but your computer's sound card is more than enough to "broadcast" the malware as the inaudible sound that interacts with other machines. It doesn't care what network a computer is on.

Scientists claims that they have created computer virus that transfers stolen data using inaudible sounds

Just using the built-in speakers and microphone in a pair of commercially available laptops, the researchers were able to transfer small amounts of sensitive data across a distance of almost 65 feet(This distance can be increased using a network of controlled devices). The Scientists build the software but the One significant drawback of the that the data transmission rate was only 20 bits per second - enough to send basic text, but too small to transfer any larger multimedia, such as video. With Such as small bandwidth, only critical information can be shared like keystrokes private encryption keys or maybe malicious commands to an infected piece of construction."

Consequences-

The attacker would probably have to be very sophisticated to be able to pull off something like this." There's not really a way to proactively protect yourself from air-gap malware. The techniques that go into employing air-gap malware are complex and can only be orchestrated by a very skilled hacker

It will be very lethal when used for Cyber Warfare a Global Digital Weapon. Government agencies can leverage this technique since they have ample money and time to hire sophisticated attacker and involve in research for developing malware which can share data at high transmission rate.


Monday, January 20, 2014

CIOs' decision Criteria may not be solely dependent on Compliance in present Dynamics

Compliance should no longer dominate CIOs’ decision making. Instead, it should be viewed as a risk, says Gartner. The research firm suggests compliance should be incorporated into risk management, rather than security being incorporated into compliance as most companies have been doing until now.

“By simply trying to keep up with individual compliance requirements, organizations become rule followers, rather than risk leaders". Compliance should be treated as a domain of risk within a formal risk management program and should not be allowed to dominate decision-making.

Compliance is treated as a legal or regulatory requirement which is evaluated based on predefined checkbox matrix. The common myth is organization feels doing so achieve Security within their functions. An organization needs to wider the boundaries and treat compliance as a risk in an overall strategy to effectively place security it's due importance.

In coming future, there will be transition drift from compliance-based to risk-based security.Compliance will be placed at a right position in CIO agenda but it won't be the only decision making a factor.

Thursday, September 26, 2013

Monday, September 23, 2013

People are Not Robots-It’s a Business

People, Process & Technology are 3 critical gears of any system. The organization is spending humongous effort in developing a consistent environment for building services, solutions, products for a community. Conceiving the services may be worrisome due to over reminded buzz world called “Cyber Security”. Cyber Security is often associated with the External hacker community and very less preference given to Internal Employee. Reason has been a trust; However, Responsibility always comes with Power which has profound root under the ground. 

“People are Not a Robot, they will try to take control of systems or react differently if the security culture is not deep penetrated inside the foundation.”

News broke this week about IBM’s latest file leak, where a former employee with access to confidential information regarding IBM’s play in cloud computing technology leaked hundreds of pages of documentation, shedding light on IBM’s weakness within the cloud computing industry. The breaches similar to this has affected the stock emotion and further reputation of the company in delivery services.  

Inside threat is the area of silence and always given second preference; however, the results are more painful than External threats. 
A survey was conducted on Insider Data Privacy, which has revealed some alarming situations



The Typical data movement practice followed are removing data was to copy it to a staging site on the Internet, such as iDisk or DropBox, with 43% choosing this channel; 36% used webmail to send out files as attachments, 29% copied information onto a USB device and 3% feels taking printout.

Data Leak Prevention system should be enforced at the foundation of the system not leaving any member out of its perimeter. This ensures data(structured/unstructured) protection to minimize the risk of a breach or a loss of intellectual property. A strong segregation of duties measures is incorporated to mitigate risk arising from Administration perspective.A careful attention should be given, so that productive working relationship of the Employee and Organization should not get restricted.

Tuesday, September 10, 2013

Cyber Crime History (1820) to Today's enforcement law’s (2013)

Cyber crime has shown a serious threat to society since many decades. We will not believe the first cyber crime recorded in late 1820.Yes, it's a shocking fact!!!
Abacus, which is thought to be the earliest form of a computer, has been around since 3500 B.C. in India, Japan, and China. Joseph-Marie Jacquard, a textile manufacturer in France, produced the loom. This device allowed the repetition of a series of steps in the weaving of special fabrics. This resulted in a fear amongst Jacquard's employees that their traditional employment and livelihood were being threatened. They committed acts of sabotage to discourage Jacquard from further use of the new technology.

Now, Technology has transverse  to many folds from standalone computers to messed network(like personal area network (PAN),local area network (LAN),home area network (HAN), storage area network (SAN),campus area network (CAN),Backbone network, Metropolitan area network (MAN), wide area network (WAN), virtual private network (VPN)) and etc. with different Technology modes.

To manage and maintain confidentiality, Integrity, and Availability of such complex system, a CyberLAW has to be enforced to minimize the challenges in the legal world. The disputes arise for any challenges, whether Statutory or otherwise, are terms as "CyberLAW".European Union, USA, United Nations Commission On International Trade Law (UNCITRAL) have already framed important laws to regulate cyberspace. In India, Information Technology Act (ITA) is also based on the UNCITRAL model, all cyber laws are contained in Information Technology Act, 2000.

The below list provide high-level analysis pertaining on Cyber Crime as associated IT LAW.

Cyber Crime
Brief Description(Example)
Relevant Section in IT Act
Punishments
Cyber Stalking
Stealthily or harass  a person or a group,  false accusations
 identity theft(tracking his chat)
43,65,66
3 years, or with fine up to 2 lakh
Cyber Pornography including Child Pornography
Publishing Obscene in Electronic Form involving children
67,67(2)
10 years and with fine may extend to 10 lakh
Intellectual Property Crimes
Source Code Tampering, Piracy, Copyright infringement etc.
65
3 years, or with fine up to 2 lakh
Cyber Terrorism
Protection against Cyber Terrorism
69
Imprisonment for a term, may extend to 7 years
Cyber Hacking
Destruction, Deletion, Alteration etc.
66
3 years, or with fine up to 2 lakh
Phishing
Banking Financial Frauds
43,65,66
3 years, or with fine up to 2 lakh

Friday, September 6, 2013

India in top 10 league for Spear Phishing

We discussed the aim of phishing and the modus-operandi of achieving it. Likewise, Spear Phishing is an attempt directed at specific individuals or companies to steal sensitive information rather than targeting to mass community. The probability of success, in this case, is much higher.India is upcoming country, with strong expansion in various verticals and specialized in providing IT Consulting services across the Global. One year back, India was not in a league of this competition; however, now it holds 3% share for hosting a phishing site. This is very less number but it looks to be an alarming situation down the line.  Today, the country has clearly established a footprint on the international cyber map for being in the list of top 10 hosts of phishing sites globally.
The most targeted Indian sites were classified in various categories - information technology (14.40%), education (11.90%), product sales and services (9.80%), industrial and manufacturing (7.30%), and tourism, travel, and transport (5.80%). 

The attack leaves a devastated footprint when targeted to specific customer-centric vertical.  Privacy protection is a crucial element of today’s  growing e-service demand.One of the most glaring attacks was the recent purchase of more than 15,000 online tickets on Kingfisher Airlines by fraudsters who somehow got hold of the credit card information of several cardholders, many of them foreign nationals. While it is not clear where the fraud originated, some estimates peg the loss to the carrier at Rs 17 crore.

In fact, Major Bank has been targeted and now in a race of taking corrective actions like user awareness and establishing a monitoring mechanism to track and block the site at Service Provider end. This does not look to be simply since it can be a target from the globe with different "Law of the Land" rules.

Countermeasures to avoid phishing attacks:
  • Do not click on suspicious links in email messages. In the case of any doubt, perform the simple step as mentioned in my previous blog (like identifying the email address in the message header and IP address) to identify if it’s a phishing mail.
  • Do Not reveal sensitive information over the call.
  • Do not enter personal information in a pop-up page or screen
  • Ensure the website is encrypted with an SSL certificate by looking for the padlock, ‘https’, or the green address bar when entering personal or financial information
  • Update your security software frequently, which protects you from online phishing
  • And lastly, Inform respective organization about the same to prevent further broadcasting.