Wednesday, January 3, 2018

Medical Records are Valuable Assets Requiring Security

            As each week passes, more medical facilities are compromised and an increasing number of consumer medical records are bundled for sale on the dark web. These to be sale-able, the medical records must hold value in some form. Without this, the medical records would not be targeted.
            The attackers are able to use this for identity theft. These medical records contain obviously charting for the patient, but also the full patient name, SSN, and other ID data, e.g. the state driver’s license number. There may also be present in the record the patient’s payment information, present in the record the patient’s payment information, including the credit card number. The patient record may also have the patient’s picture. With this information and data, credit card fraud and identity theft is moderately easy. This could occur repeatedly occur over the years. The records could be sold repeatedly over the years, repeating the cycle.
            This theft may not be noticeable for years. The attackers tend to slowly and methodically extract value from this. In comparison, a credit card is canceled and a new card issued relatively quickly after fraud is detected.
            The medical records may be used for Medicare Fraud. This may involve fraudulent billing and over-billing. With a mass-amount of records, this could be rather lucrative for the deviants.
            The affected parties have a limited number of actions to take when this occurs. The consumer could contract with a third-party service to monitor their personal credit report. This has been met with mixed results as these services don’t always stop the credit reports from being pulled, as personally experienced. The other primary option is for the consumer to freeze their account. These options also have their own issues.


Tuesday, January 2, 2018

Compromises; It's not just for banks anymore!

The typical target in the past has been entities holding confidential, sensitive information. This is readily marketable and depending on the information, may be significantly valuable. This has been experienced in the medical field for the last few years. For example, the number of retail clients visiting stores in a region of the U.S. would be less valuable than schematics from a DoD contractor for the new jet or strategy documents from the FDIC.
            The attackers have switched their focus a bit to another industry and entity, which happens to hold sensitive information. The latest notable compromise victim is involved with the automobile finance companies. Employees of the Nissan Canada Finance (NCF) and Infiniti Financial Services Canada detected on December 11, 2017 a portion of the customer’s data had been compromised. This did not affect every one of their customers. The data exfiltrated may have contained the names, addresses, details of the vehicle, VINs, credit scores, loan amounts, and information on the monthly payments. This is the second known time Nissan had been targeted, with the prior instance being in 2012.
            Seemingly, this is not very valuable to the unauthorized third party. Upon further review, this is actually quite useful. The holder of the data has the person’s private, relevant information. With the social security number, the person is able to fully validate the identity of another person. Banks have begun to use information from the user’s credit report for a secondary source of identification. If the person seeking to assume the other’s identity had this, the impersonator could easily use.
It is curious the attack had waited this long to focus on and attack these entities. The businesses do hold a large amount of sensitive information and may not have deemed themselves a sufficient target. The recent breach and outward data flow show any entity is a target, especially those with helpful information.



Sunday, December 31, 2017

Integrate InfoSec into the Hospitality Industry

The hospitality industry has a single focus on ensuring their guests have the optimal experience relative to their facility. This is the same with the medical and other fields; society wants people to specialize in their fields, versus generalizing in too many. If you are having heart surgery, you want the surgeon to be a specialist and not a general practitioner.

The hospitality industry is no different. As part of the operating process, the hotels and other facilities collect a mass amount of data from the clients. Each client has to pay for their room and other services, which is generally done with a credit card. This is valuable to the attackers, as the data may be sold. In recent history though, the industry has not done a fantastic job in protecting their client's data. A particularly glaring issue occurred with the Wyndham Hotels with the 2008 and 2009 compromises. The hotel in late 2015 settled with the Federal Trade Commission regarding charges the hotel did not do enough in order to protect the data. This arose from three breaches the hotel experienced with their client's data being exfiltrated. The process to resolve the issue was not inexpensive, as evidenced by the attorney fees and the fines.

Until this point, the hospitality industry has not given InfoSec a significant amount of attention. In comparison, other industries have declared this at a greater level of pertinence. For example, the DoD contractors, municipalities, financial services, medical, banking, and others have increased the focus and spending on this. The commonality with these is the entity computer system had been compromised, data exfiltrated, and fines from the FCC in specific cases.

This lack of focus may be a function of the entities working on their goal of achieving the best service for their clients. InfoSec, while vital, had not been significantly considered integral to their mission. Although not entirely within the distinct area involving their operations, InfoSec is still a supporting facet of their business.

Over the last few years, this has begun to change. The businesses are beginning to recognize each hospitality entity is the steward and responsible for their client's confidential and sensitive information. This data is sought by the attackers from the globe. The data being stored leads the reasons for attacks to occur. If the attack is successful, the hotel's client information (name, physical or mailing addresses, email addresses, credit card numbers, etc.) is removed by unauthorized parties.

This focus is expected to increase as this hospitality industry continues to increase their offerings geographically. The increase is relevant to InfoSec as the entities will be managing more data from many more regions and countries. Without this in place, the liability when there is a breach will only increase, especially with the GDPR coming online in the near future.






Mobile Device Attacks

Mobile devices have infiltrated society in many forms. People use their smartphones, tablets, laptops, and other devices in the coffee shops, malls, grocery stores, and too many other locations to note. These also have been adopted by children as they learn the many uses of technology.

These IoT devices have substantially improved the user experience (UX) and significantly increased the number of units in use along with productivity. As you walk through public areas, most people have these devices and actively using them.

One area within this realm which has not been exceptionally addressed in InfoSec. These devices hold a mass amount of data, mundane and confidential. The data also would have various levels of confidentiality involved. The person's physical address, in the grand overview, would not be as marketable as the social security number, parent's last names. This data is being targeted by the attackers.

This was recently researched by Check Point. Their research indicated 100% of the respondents, businesses located throughout the world, badly experienced malware on their mobile assets The sample consisted of 850 businesses on four continents. The focal point of the attacks were both the Android and iPhone devices.

The attacks were not isolated within each business, but there were many instances of each business. The study also noted 89% of the businesses had the opportunity to manage man-in-the-middle attacks (MitM). On a secondary level, 75% of the organizations also experienced their devices becoming compromised, as defined with the device being rooted or jailbroken.

The results indicate the mobile devices are clear targets. With the devices themselves, the Android systems were less secure than the iOS and Windows.

With these focussed attacks, it would appear defending against would be nearly impossible. With sufficient and regular training with the staff, this may be remediated to a manageable level. When the staff understands what not to do, what to not click on, what to watch for, etc., there are fewer instances of issues.

Tuesday, December 19, 2017

What is new again: Part II

An aspect of human nature not explored sufficiently is the lack of memory permanence. There is the distinct length of time people remember major system compromises. After this point, the issues leading up to the compromise, implications for the company, effects for the clients and associates are forgotten. This is not a new phenomenon and has been verified by several retail business breaches. After the breach notification, the sales revenue decreases for a bit, however later rebounds as if nothing ever happened.

There is, unfortunately, the same effect with malware. A programmer with a great idea for new malware creates this, the malware is presented in the wild, the malware works for a bit of time, is red-flagged, and its use is no longer needed. In the environment, we are seeing the old malware getting a new life and being re-introduced, perhaps with a nuance to adjust its signature to avoid notice from the AV providers. A recent example has been macros in Word and Excel. These were a significant issue over a decade ago. These were forgotten as viable issues for a rather significant amount of time until these were re-introduced. These were effective once again for a brief period of time until the new application is noticed, and the cycle begins again. Another incident has occurred with this. Recently, a vulnerability dating back 19 years re-appeared. This affects the RSA implementation with at least eight vendors. This vulnerability has been termed ROBOT, an acronym for Return of Bleichenbacher's Oracle Attack.

When exploited, this allows the others to decrypt and encrypt the RSA function applying the private key which had been configured previously on the TLS servers where the vulnerability was located. This issue was first noted by Daniel Bleichenbacher, a Swiss cryptographer. The vulnerability and subsequent attack are specifically applicable to RSA based PKCS #1 v1.5 encryption as utilized in SSLv2.

This will certainly not be the last attack that will be recycled. This will continue as long as our memories remain short.

Sunday, December 17, 2017

Critical Infrastructure (CI) Targeted Again and Again and Again

Critical infrastructure (CI) is one of the underlying backbones of our civilization. This aspect supports virtually all we are actively involved in. If you like to use electricity for your electronics (e.g. computers, laptops, tablets, television, radio, etc.), fresh water, sewage leaving your home, etc., then a certain new malware sample should grab your attention.

Malware directed at the energy industry is not new. There have been dams attacked in the US. nuclear power plants across the globe, and other CI industries. The equipment implemented in the industries also has been targeted for their respective vulnerabilities.

The latest malware is an example of the latter. This targets the Triconex Safety Instrumented System (SIS) manufactured by Schneider Electric and has been named Triton or Tricis. This equipment is part of the industrial control system (ICS) for the utilities. This is designed to work in an autonomous fashion to monitor systems within the utility and shut a system down if there is a safety issue. This malware was coded to when implemented against the vulnerability to read and write programs and functions, along with querying the SIS controller. The attacker, with the deployed malware, is able to modify the SIS logic to shut down, indicating an unsafe reading, when the system may be operating fine without an issue.

There naturally would be financial issues to the utility, however, there may also be damage tot he equipment and facility if this were to be reversed and the equipment was to allow for unsafe conditions to continue unchecked.

The IC and ICS systems will continue to be targeted as time passes. With an attack here, the result of the compromise would rather significant detriment.

Wednesday, December 6, 2017

Let's automate (security) and not procrastinate


With each dawn, there are new stories relating there has been yet another compromise and a mountain of data had been exfiltrated via an "advanced hack" that allegedly no one could have defended against. Notwithstanding many of these are oversights, there is a form of assistance from within the organization that is more of an organic method of assistance. This may not be the panacea that too many are seeking, however it certainly would be an assistance.

A central issue is the lack of qualified, skilled employees in the market. This has been noted repeatedly. The fix for this is not in the short-term frame. This involves training, change of mindset, and other paradigm shifts to take a full effect. One avenue, overlooked by too many is utilizing automation to assist with the task. To fully review logs, gather material, and perform the simple tasks takes the staff time to complete. This may take hours that could be used for much greater and impactful duties. By automating these tasks, the time the staff was spending pulling reports, analyzing for trends, and other activities would be freed up. The scripts don't need to be extremely over-complicated, but written to simply do the task.

To further extend the usefulness of this, simple machine learning could be applied. To ensure this is indeed adding value, this could be supervised until the app would be completing its tasks to the acceptance of management. This again would not need to necessarily delve into the minutiae initially. This step may be taken at some point later on when the comfort level is present. This is merely one manner to assist with the time crunch felt in the industry.