Tuesday, December 5, 2017

Be Careful What You Share on Social Media

            People are focused on posting their daily lives on the various social media sites. This may include vacation photos and updates, birthday parties, sporting events, business trips, dinner parties, and virtually any other activity. The users do this without any reservation or concerns.
            The persons don’t appreciate the reach of the internet into their data. Unfortunately too many people don’t secure their social media accounts. Without this in place, other people, especially those who have no relevant business with the target, have access to the person’s private life. This includes the details of when they went on vacation, who they went with, where they stayed, activities while there, etc. With the proper level of security applied, the issues associated with this would be mitigated.
One issue with this involves identity theft. There are clear risks with sharing too much personal information with the public and friends. This data, which may be readily available, is able to be used by attackers to gain leverage on the person/target. As an example, with the prior noted information, the attacker could work towards impersonating the user with various vendors that work with the person/target, such as the local bank. The attacker would start small and build on this in creating the background and gather private, confidential data for the person. As the attacker exfiltrates more information regarding the user, the basis of information grows and allows for a greater potential for the attacker to contact more organizations of greater value the user is in contact with to exfiltrate more data and assets. For example, there are certain organizations or departments that don’t allow a person access unless the full, thorough authentication process is in place and used. At some point in time, the attacker, when enough target data is secured, may take over the identity completely and move assets (retirement funds, cash, etc.) from the user.

A little information tends to be dangerous for the person securing this, while a great amount of information may be devastating for the target. Users need to think about what data and information they are actively putting on the internet in the social media sites, as this could prove to be a disaster for them for the future. 

Yes, logs are important

In recent history there have been rather extensive and significant breaches affecting millions of people. This action has provided criminals with a rather extensive amount of data to sell and resell on the darkweb. This has a rather substantial effect on the affected consumers. They have three options to deal with this. The consumers may do nothing and hope the criminals do absolutely nothing with the personal data. This is not the optimal situation and hardly could be recommended. The altterantive is an affirmative defense of freezing one's credit or contacting with a service to monitor their credit.

For the breached party, the consequence is a bit more serious, especially in the healthcare industry. Granted data was still exfiltrated, however in this case there are also healthcare records in addition to the usual records, inclusive of the  SSN. At this point, the HIPPA statute penalties may become an issue. On an alternative front, the entity may face civil lawsuits from the consumers. This, based on the number of the clients affected, may be millions of dollars.

A recent example of a breach gone really bad occurred with eClinicWorks, an electronic health records (EHR) vendor. There is presently a class action suit for nearly $1B based on the firm's software allegedly not being able to provide reliable health information for the patients. This directly would affect millions of patients. Effectually the patients have the "opportunity" to monitor their credit reports, health insurance reporting, and too many other data points to regularly monitor for abuse.

This was only a portion of the issue however. The firm also agreed to a $155M settlement and entered into a five-year corporate integrity agreement with the Department of Health and Human Services Office of the Inspector General.

These relatively serious legal proceedings were initiated after the business allegedly did not adhere to its claim of meeting the HTIECH Act EHR incentive program's certification requirement. Per the civil suit, the claim was the incorrect medical data was displayed, multiple patient's data shown at the same time, incorrect medical histories were displayed, and pertinent to the InfoSec field, the audit logs did not accurately record the user's actions, and other issues.

These deficiencies and oversights have led to a financial repercussion for the business, reputational risk, and potential loss of revenue for future time periods. Germane to the InfoSec industry is the log issue. With the lack of operational security stance, the logs are virtually useless and cannot be depended on. With these providing inaccurate user action logs, these would not be useful and be pointless.

Unfortunately, this is not an isolated case. Examples of poor coding and data flows are in the industry creating issues for business and the consumers.

Phishing: It's not what is for dinner

            Phishing has been in use in one form or another probably a week after the first email account was used by consumers. Phishing has become glaringly prevalent in today’s society. This clogs up the Spam folders daily across the U.S. The attackers have operationalized phishing as a vector to compromise the user’s information, data, email, credentials, and any other facet that has value. This has become so popular and used as much as it is due to the ease of application. The technical requirements for this are minor. The phisher has to create a moderately believable email generally without significant grammar or spelling errors, which is not difficult. This may involve a bank, sale at a retail business, sale on pharmaceuticals, or any other possible email that is appropriate.
            The more productive and revenue generating phishing scams or campaigns have involved ransomware or the executive wire scam. Most are familiar with the ransomware phishing exploit, as it has been in the news more frequently. With this the user opens a link or attachment that appears to be fine, however is actually malicious in nature. The system, network segment, network, etc. is encrypted. The attackers later offer to provide the decryption key…for a fee.
            The executive wire scam has predominantly taken the form of someone in accounting or finance receiving an email directing them to wire funds, varying per target from a few thousand to millions, dependent on the target, what was encrypted, the industry, etc. The usual email is rather demanding, stating the person has to wire the money in the next few hours, the executive sending the email is in a meeting or would not be accessible, and it is imperative that this be sent. These both are very low tech attacks, which work on the user’s oversight and willingness to do the job and keep the executive happy.
            All is not lost though. There are many options the users need to be aware of in order to limit the risk of this continuing to happen. For instance, the bank is not going to send the user a link in an email with a message directing the user to click on a link or to provide the credentials on the email. Generally, an invoice does not need to be paid within a few hours or a discount would be lost. As a rule of thumb, the discount period is a few weeks, not hours. Although pet pictures are wonderful, strangers are not going to email these to you. Users generally don’t purchase pharmaceuticals online from a firm they have never heard from and their workplace is not associated with.
            One tool that works wonders is simple communication. If an email arrives and demands a payment within a very short amount of time and the sending party directly, aggressively states that they are not accessible, simply check if they are actually on vacation, if they are in a meeting, send a quick email to the person while not replying to the email that was received for authentication, or just make a quick call. This only takes a moment and has the potential to save a large amount of money and embarrassment.



Solar Panels as a Target

            Alternative and renewable energy sources have become more important and visible over the last few years. This is due to many factors, including the price in oil fluctuating, oil being a finite resource, the nation focusing on being less dependent on oil from other countries, and the clear view of the environmental concerns.
            As the alternative energy sources have been produced to a greater level, there are more choices for consumers. Early on, there was solar and wind. As time passed more products within each were added and to a greater extent. For instance, there were consumers and users using a few of these on their property. Now there are solar farms across the U.S. and wind farms on land and in the sea. As a bi-product with the increased number of products is the security testing. There are by far more products available, and security has been applied at a rudimentary level or brushed aside.
Target
            This testing methodology was put into place with a recent product. With solar panels, an essential piece of the equipment is the inverter. This allows the solar panel to convert the DC (direct current) to AC (alternating current). With the subject solar panels, this was connected to the internet. The vulnerability noted was researched and published by the Dutch InfoSec firm ITsec.
Exploit
            The security researcher found 17 vulnerabilities. With this attack, the security researcher was able to take control of the solar panel. If the attacker were able to gain control over a significant number of solar panels, much like the IoT bot army, the solar panels could be turned off or on at the same time. Individually, this seemingly would not appear to be a significant issue. The integral portion of this is that the solar panels are connected to the grid. If this were to be done with a large number, there would be a significant fluctuation in the power grid. This would cause a rather large and nearly instant power imbalance, which could force the grid to power off.


            From a third party’s view, this would not be an issue. The additional component not noted in significant numbers in the U.S. is the connectivity. With this factor, a large number of solar panels being turned off or on at any distance would be a rather significant detriment for the utility. 

Gorilla Glue Data Not Secure

            Gorilla Glue is known for their excellent set of products, and also the commercials. What has not been overly publicized, naturally, is the compromise from last year. The attack was spearheaded by The Dark Overlord. The hackers had previously attacked medical organizations and demanded a significant ransom. The group also attacked West Park Capital, an investment bank. In this instance the attacker claimed to have over 500GB of data from Gorilla Glue. Included in this mass amount of data was IP, product designs, access to company email accounts, Dropbox, financial spreadsheets, invoices, strategy documents, presentations, contracts with banks, and other confidential documents (Cox, 2016; Bisson, 2016). This was a rather brazen claim. Without some form of authentication, there would be a minimal amount of credibility. To circumvent this issue, The Dark Overlord forwarded 200MB of files to Motherboard (Cox, 2016). These were also forwarded to Gorilla Glue as evidence.
Ransom
            As with any attack of this nature, it is presupposed that there would be the threat of releasing the data if a fee is not paid. This was not an exception. As with the two prior victims (a medical group and the investment bank), Gorilla Glue was provided with a “handsome business proposal” (Bisson, 2016). There were two primary options-pay or don’t. The paying has issues of not receiving the data, the data being released later, malware being left on their system, etc. With not paying the immediate threat would have been the release of their data, short-term loss of respect, and damage.

References
Bisson, D. (2016, November 18). Gorilla glue finds itself in sticky situation after hackers steal data. Retrieved from https://www.grahamcluley.com/gorilla-glue-finds-sticky-situation-hackers-steal-data/

Cox, J. (2016, November 17). Hackers claim theft of data from gorilla glue. Retrieved from http://motherboard.vice.com/en_au/read/hackers-claim-theft-of-data-from-gorilla-glue

Machine Learning to Assist with InfoSec

            Computers are rather adept at a large number of tasks, from the mundane to complex and dangerous. The users may want statistics applied to columns of numbers, list of prime numbers, or any other task that would require a computing ability within a parameter of steps. The systems, by design, process items faster, are able to complete complex computations at such a quicker pace, and are able to compare correlations faster than a human could ever fantasize about.
Given this speed, it is no wonder users are gladly able to hand-off the tasks requiring this level of processing so quickly. This makes life a bit easier for the user and more efficient for all parties, human and not.
Machine learning (ML) offers a number of benefits to industries not focused on nearly instant processing. This is especially true in the case with the InfoSec field. This industry has such a diverse population and set of duties, intuitively finding a match with the duties may take a bit of time. The Admin or other person responsible for this integration, at this point, is not able to just load this onto the servers and not maintain the program. This may be a completely workable option in the very near future, given Google’s new AI iteration, which learns on its own. This would need to be reviewed periodically for adjustments. This could be for the configuration itself, to adjust the algorithms, or other functionality.
ML and AI (eventually) is able to specifically assist with several InfoSec functions and issues. One area is to limit the spear phishing attack effectiveness. Phishing continues to be a significant issue. This has and continues to be exceptionally profitable for the attackers. This continues to be a severe detriment for the user, financially and operationally. These attacks steal and exfiltrate money, credentials, data and other items that may be of value which could be sold by the successful attackers. The attackers use social media, business websites, and other sources for the data to make the attacks a success. In general, the greater amount of data, the greater the potential for the attacker to mislead the target into clicking a link or a picture, visiting a malicious URL, or following other nefarious instructions to infect their systems. The ML algorithm may be used to assist with this. The ML algorithm may use the metadata located in the emails. This may be accomplished while maintaining the user’s privacy. The email header and a sampling of the email’s body makes this able to provide data as to if the subject email is representative of a malicious, spear phishing email. The ML algorithm is able to review the behavior evidenced by the email to gauge if this likely would be an phishing or spear phishing email.
            The ML algorithms are able also to work on watering hole attacks. These appear to be a perfectly legitimate website. With these though, the sites or applications would have been compromised, or the sites themselves may be false and malicious. These may also lure people to put in their credentials for other sites. In this case, the ML algorithm may identify interactions encountered before, creating a baseline of behavior to use. This may be compared to the present activity to gauge if this would likely be a malicious activity.
            This list is clearly very short and is only a small sample of the capabilities and potential uses for ML in InfoSec. There are many more places and uses for ML and the respective algorithms. This will be a significant benefit for the users, business, and a detriment for those intent on attacking the enterprise. 

'Tis the Season

Seemingly every year about this time, the phishing campaigns are presented to the consumers. The phishing emails have taken various forms to the consumers. There have been the emails from “shipping carriers” to several individuals stating their packages, all with the same tracking number, is out for delivery. “Vendors” forwarding emails with their new products you need to purchase for your friends and family as the perfect gifts are regularly encountered. These may be also time oriented, stating the Cyber-Monday sale is being extended for a very limited amount of time, so you need to click on the link for the retailer to have the special discount code. These emails are an attractive nuisance, yet are still effective to a point.
This year, I did receive an interesting contact. This was in the form of smishing via text message. The form was “Notice-[phone number] from [Bank]. Code: Visa-Debit Locked. Call us now at 202-852-xxxx. Thank you.” This was notable as it utilized a few of the motivators a phishing attack normally would. During the holiday season, people need access to their funds for the normal everyday purchases, but more to the point for holiday shopping for family and friends. This message indicates, if the consumer believes it, they are cut off from their funds, which they would need. Also, there is the thought that someone may have compromised their account, otherwise what would make the bank cease activity on the account, until the consumer contacts them.
This is also a teachable moment. Bank’s do have this option available for their customers. The customers also have the option to receive other text messages with the account balance, checks clearing, or other activity on the account. The form of the text was relatively close to what would normally be encountered by the consumers. In this case, the phone number was highlighted. If the consumer were to utilize the ease of use and press the option for the phone to call, there could have been a significant issue. The consumer should, as with emails, not presume the link is valid. In this instance the number was called, and the phone number allegedly to my bank was not in service and had been disconnected. The consumers may learn from this instance to make their experience more secure by not automatically trusting text messages as they arrive on their phone.