The hospitality industry has a single focus on ensuring their guests have the optimal experience relative to their facility. This is the same with the medical and other fields; society wants people to specialize in their fields, versus generalizing in too many. If you are having heart surgery, you want the surgeon to be a specialist and not a general practitioner.
The hospitality industry is no different. As part of the operating process, the hotels and other facilities collect a mass amount of data from the clients. Each client has to pay for their room and other services, which is generally done with a credit card. This is valuable to the attackers, as the data may be sold. In recent history though, the industry has not done a fantastic job in protecting their client's data. A particularly glaring issue occurred with the Wyndham Hotels with the 2008 and 2009 compromises. The hotel in late 2015 settled with the Federal Trade Commission regarding charges the hotel did not do enough in order to protect the data. This arose from three breaches the hotel experienced with their client's data being exfiltrated. The process to resolve the issue was not inexpensive, as evidenced by the attorney fees and the fines.
Until this point, the hospitality industry has not given InfoSec a significant amount of attention. In comparison, other industries have declared this at a greater level of pertinence. For example, the DoD contractors, municipalities, financial services, medical, banking, and others have increased the focus and spending on this. The commonality with these is the entity computer system had been compromised, data exfiltrated, and fines from the FCC in specific cases.
This lack of focus may be a function of the entities working on their goal of achieving the best service for their clients. InfoSec, while vital, had not been significantly considered integral to their mission. Although not entirely within the distinct area involving their operations, InfoSec is still a supporting facet of their business.
Over the last few years, this has begun to change. The businesses are beginning to recognize each hospitality entity is the steward and responsible for their client's confidential and sensitive information. This data is sought by the attackers from the globe. The data being stored leads the reasons for attacks to occur. If the attack is successful, the hotel's client information (name, physical or mailing addresses, email addresses, credit card numbers, etc.) is removed by unauthorized parties.
This focus is expected to increase as this hospitality industry continues to increase their offerings geographically. The increase is relevant to InfoSec as the entities will be managing more data from many more regions and countries. Without this in place, the liability when there is a breach will only increase, especially with the GDPR coming online in the near future.
Miel, LLC Cybersecurity Architecture, Design, and Engineering Cybersecurity architecture is a requirement in today's environment. If you don't address cybersecurity in your organization, there will be problems. Miel, LLC offers architecting and embedded systems hacking services provide proactive cybersecurity services to improve your defenses, so you aren't reactive. Miel, LLC Cybersecurity Architecture, Design, and Engineering 810-701-5511 charles.parker@mielcybersecurity.net
Sunday, December 31, 2017
Mobile Device Attacks
Mobile devices have infiltrated society in many forms. People use their smartphones, tablets, laptops, and other devices in the coffee shops, malls, grocery stores, and too many other locations to note. These also have been adopted by children as they learn the many uses of technology.
These IoT devices have substantially improved the user experience (UX) and significantly increased the number of units in use along with productivity. As you walk through public areas, most people have these devices and actively using them.
One area within this realm which has not been exceptionally addressed in InfoSec. These devices hold a mass amount of data, mundane and confidential. The data also would have various levels of confidentiality involved. The person's physical address, in the grand overview, would not be as marketable as the social security number, parent's last names. This data is being targeted by the attackers.
This was recently researched by Check Point. Their research indicated 100% of the respondents, businesses located throughout the world, badly experienced malware on their mobile assets The sample consisted of 850 businesses on four continents. The focal point of the attacks were both the Android and iPhone devices.
The attacks were not isolated within each business, but there were many instances of each business. The study also noted 89% of the businesses had the opportunity to manage man-in-the-middle attacks (MitM). On a secondary level, 75% of the organizations also experienced their devices becoming compromised, as defined with the device being rooted or jailbroken.
The results indicate the mobile devices are clear targets. With the devices themselves, the Android systems were less secure than the iOS and Windows.
With these focussed attacks, it would appear defending against would be nearly impossible. With sufficient and regular training with the staff, this may be remediated to a manageable level. When the staff understands what not to do, what to not click on, what to watch for, etc., there are fewer instances of issues.
These IoT devices have substantially improved the user experience (UX) and significantly increased the number of units in use along with productivity. As you walk through public areas, most people have these devices and actively using them.
One area within this realm which has not been exceptionally addressed in InfoSec. These devices hold a mass amount of data, mundane and confidential. The data also would have various levels of confidentiality involved. The person's physical address, in the grand overview, would not be as marketable as the social security number, parent's last names. This data is being targeted by the attackers.
This was recently researched by Check Point. Their research indicated 100% of the respondents, businesses located throughout the world, badly experienced malware on their mobile assets The sample consisted of 850 businesses on four continents. The focal point of the attacks were both the Android and iPhone devices.
The attacks were not isolated within each business, but there were many instances of each business. The study also noted 89% of the businesses had the opportunity to manage man-in-the-middle attacks (MitM). On a secondary level, 75% of the organizations also experienced their devices becoming compromised, as defined with the device being rooted or jailbroken.
The results indicate the mobile devices are clear targets. With the devices themselves, the Android systems were less secure than the iOS and Windows.
With these focussed attacks, it would appear defending against would be nearly impossible. With sufficient and regular training with the staff, this may be remediated to a manageable level. When the staff understands what not to do, what to not click on, what to watch for, etc., there are fewer instances of issues.
Tuesday, December 19, 2017
What is new again: Part II
An aspect of human nature not explored sufficiently is the lack of memory permanence. There is the distinct length of time people remember major system compromises. After this point, the issues leading up to the compromise, implications for the company, effects for the clients and associates are forgotten. This is not a new phenomenon and has been verified by several retail business breaches. After the breach notification, the sales revenue decreases for a bit, however later rebounds as if nothing ever happened.
There is, unfortunately, the same effect with malware. A programmer with a great idea for new malware creates this, the malware is presented in the wild, the malware works for a bit of time, is red-flagged, and its use is no longer needed. In the environment, we are seeing the old malware getting a new life and being re-introduced, perhaps with a nuance to adjust its signature to avoid notice from the AV providers. A recent example has been macros in Word and Excel. These were a significant issue over a decade ago. These were forgotten as viable issues for a rather significant amount of time until these were re-introduced. These were effective once again for a brief period of time until the new application is noticed, and the cycle begins again. Another incident has occurred with this. Recently, a vulnerability dating back 19 years re-appeared. This affects the RSA implementation with at least eight vendors. This vulnerability has been termed ROBOT, an acronym for Return of Bleichenbacher's Oracle Attack.
When exploited, this allows the others to decrypt and encrypt the RSA function applying the private key which had been configured previously on the TLS servers where the vulnerability was located. This issue was first noted by Daniel Bleichenbacher, a Swiss cryptographer. The vulnerability and subsequent attack are specifically applicable to RSA based PKCS #1 v1.5 encryption as utilized in SSLv2.
This will certainly not be the last attack that will be recycled. This will continue as long as our memories remain short.
There is, unfortunately, the same effect with malware. A programmer with a great idea for new malware creates this, the malware is presented in the wild, the malware works for a bit of time, is red-flagged, and its use is no longer needed. In the environment, we are seeing the old malware getting a new life and being re-introduced, perhaps with a nuance to adjust its signature to avoid notice from the AV providers. A recent example has been macros in Word and Excel. These were a significant issue over a decade ago. These were forgotten as viable issues for a rather significant amount of time until these were re-introduced. These were effective once again for a brief period of time until the new application is noticed, and the cycle begins again. Another incident has occurred with this. Recently, a vulnerability dating back 19 years re-appeared. This affects the RSA implementation with at least eight vendors. This vulnerability has been termed ROBOT, an acronym for Return of Bleichenbacher's Oracle Attack.
When exploited, this allows the others to decrypt and encrypt the RSA function applying the private key which had been configured previously on the TLS servers where the vulnerability was located. This issue was first noted by Daniel Bleichenbacher, a Swiss cryptographer. The vulnerability and subsequent attack are specifically applicable to RSA based PKCS #1 v1.5 encryption as utilized in SSLv2.
This will certainly not be the last attack that will be recycled. This will continue as long as our memories remain short.
Sunday, December 17, 2017
Critical Infrastructure (CI) Targeted Again and Again and Again
Critical infrastructure (CI) is one of the underlying backbones of our civilization. This aspect supports virtually all we are actively involved in. If you like to use electricity for your electronics (e.g. computers, laptops, tablets, television, radio, etc.), fresh water, sewage leaving your home, etc., then a certain new malware sample should grab your attention.
Malware directed at the energy industry is not new. There have been dams attacked in the US. nuclear power plants across the globe, and other CI industries. The equipment implemented in the industries also has been targeted for their respective vulnerabilities.
The latest malware is an example of the latter. This targets the Triconex Safety Instrumented System (SIS) manufactured by Schneider Electric and has been named Triton or Tricis. This equipment is part of the industrial control system (ICS) for the utilities. This is designed to work in an autonomous fashion to monitor systems within the utility and shut a system down if there is a safety issue. This malware was coded to when implemented against the vulnerability to read and write programs and functions, along with querying the SIS controller. The attacker, with the deployed malware, is able to modify the SIS logic to shut down, indicating an unsafe reading, when the system may be operating fine without an issue.
There naturally would be financial issues to the utility, however, there may also be damage tot he equipment and facility if this were to be reversed and the equipment was to allow for unsafe conditions to continue unchecked.
The IC and ICS systems will continue to be targeted as time passes. With an attack here, the result of the compromise would rather significant detriment.
Malware directed at the energy industry is not new. There have been dams attacked in the US. nuclear power plants across the globe, and other CI industries. The equipment implemented in the industries also has been targeted for their respective vulnerabilities.
The latest malware is an example of the latter. This targets the Triconex Safety Instrumented System (SIS) manufactured by Schneider Electric and has been named Triton or Tricis. This equipment is part of the industrial control system (ICS) for the utilities. This is designed to work in an autonomous fashion to monitor systems within the utility and shut a system down if there is a safety issue. This malware was coded to when implemented against the vulnerability to read and write programs and functions, along with querying the SIS controller. The attacker, with the deployed malware, is able to modify the SIS logic to shut down, indicating an unsafe reading, when the system may be operating fine without an issue.
There naturally would be financial issues to the utility, however, there may also be damage tot he equipment and facility if this were to be reversed and the equipment was to allow for unsafe conditions to continue unchecked.
The IC and ICS systems will continue to be targeted as time passes. With an attack here, the result of the compromise would rather significant detriment.
Wednesday, December 6, 2017
Let's automate (security) and not procrastinate
With each dawn, there are new stories relating there has been yet another compromise and a mountain of data had been exfiltrated via an "advanced hack" that allegedly no one could have defended against. Notwithstanding many of these are oversights, there is a form of assistance from within the organization that is more of an organic method of assistance. This may not be the panacea that too many are seeking, however it certainly would be an assistance.
A central issue is the lack of qualified, skilled employees in the market. This has been noted repeatedly. The fix for this is not in the short-term frame. This involves training, change of mindset, and other paradigm shifts to take a full effect. One avenue, overlooked by too many is utilizing automation to assist with the task. To fully review logs, gather material, and perform the simple tasks takes the staff time to complete. This may take hours that could be used for much greater and impactful duties. By automating these tasks, the time the staff was spending pulling reports, analyzing for trends, and other activities would be freed up. The scripts don't need to be extremely over-complicated, but written to simply do the task.
To further extend the usefulness of this, simple machine learning could be applied. To ensure this is indeed adding value, this could be supervised until the app would be completing its tasks to the acceptance of management. This again would not need to necessarily delve into the minutiae initially. This step may be taken at some point later on when the comfort level is present. This is merely one manner to assist with the time crunch felt in the industry.
Message for the DoD: Security, It's Not just for Operations
Data comes in all forms and sizes. The composition of this also varies greatly dependent on the data owner. One actionable items regardless of the data composition is security. The data requires some form of security to be applied to it to keep unauthorized parties to access it. This difficult lesson has been learned by many organizations over the years with data compromises of differing magnitudes and costs to them. One of the latest involved the Department of Defense (DoD). The DoD happened to leave 1.8B social media and forum posts written by users from across the planet on a server. Normally, this would not be a notable occurrence. These posts however were placed on three Amazon S3 servers. These databases were owned by the US Central Command (CENTCOM) and the US Pacific Command (PACOM).
The issue is the data was not secured or protected. These could have been access by virtually anyone. When the servers were acquired by the DoD, the persons in charge for the Amazon S3 servers did not configure them correctly. This issue is not new, as this oversight has occurred several times to high level organizations within the last 12 months. The researcher who did find this lack of security did act responsibly and contacted the DoD. The Amazon services and databases were appropriately secured soon thereafter.
When working with the public's data, there is a certain level of responsibility and accountability. With the resources available at the DoD, this should not have happened. Regardless this oversight was corrected. The lessons to pull from this episode are many, which may be applied to other's workplaces. The person's with the appropriate level of knowledge and skills on topic should be doing the work. Simply pulling someone without the requisite level of skill is not a good idea. Once implemented, test the work done to ensure it actually works. Without this, the hope is the work was done correctly.
Tuesday, December 5, 2017
Connected Vehicles: Android presents another issue
A new or newer car is a significant investment for most. As a rule of thumb most people don’t have the ability to write a check for one of these vehicles. One of the selling points to entice the new buyers has been the connected features of the vehicles. Although this aspect is well-known, this feature uses a smartphone application to connect the smartphone to the vehicle. This application turns the smartphone into a remote control for the vehicle. The owner is also able to interact with the internet through the head unit (HU) of the vehicle. With all of this connectivity there are several functions, including, the user is able to start the car in January from their office, lock/unlock the vehicle doors from virtually anywhere, access music, and a number of other functions which are benefit to the user. This appears to be a great function. There are however issues to be resolved.
Issue
The security on this topic has tended to be overlooked with this area. The smart phone and vehicle applications have tended to be under-researched and studied. This is and continues to be evidenced by this connection and attack points historically being an issue and compromised in relatively many of the manufacturers. Kaspersky Labs elected to test seven of these applications native to the Android platform engineered to interact with the vehicles. These are Android applications, however are coed by the car manufacturers and third party dev op teams.
The sample consisted of seven applications. The target points for this experiment were reverse engineering of the application, if the GUI was adequately secured, if there was an integrity check with the application, and if encryption was applied to the user name and password. The research indicated the application code was not obfuscated, the username and password were not encrypted, there was no application integrity checks, and other insecure features. These applications did not incorporate even the basic security features. The applications and manufacturers were not noted as the researchers did not want these to be targeted by the attackers. This experiment also indicated the systems were open to credential theft.
Analysis
The applications basically controlled access to the vehicle and its functions, acting as a gate. Unfortunately the gate was not locked and the handle easily lifted. A deviant and attacker would be able to gain access to the vehicle’s interior using these insecure features. From here, the attacker would be able to steal the vehicle. As noted this is a rather blatant issue that has been problematic for years with many different manufacturers.
Closing
The vehicle has a great amount of respect for the vehicle. The owner and user do not want the vehicle to be vandalized and stolen. When the owner purchased the vehicle they bargained for, the person was not expecting the connectivity and application to be insecure and open to a form of vandalism. The level of insecurity allows for the vehicle to be attacked from many points. This could have been remediated with better planning or coding.
Resources
Greenberg, A. (2017, February 16). Android phone hacks could unlock millions of cars. Retrieved from https://www.wired.com/2017/02/hacked-android-phones-unlock-millions-cars/
Kuzin, M., & Chebyshev, V. (2017, February 16). Mobile apps and stealing a connected car. Retrieved from https://securelist.com/analysis/publications/77576/mobile-apps-and-stealing-a-connected-car
Zorz, Z. (2017, February 17). Insecure car-controllering android apps are a boon for car thieves. Retrieved from https://www.helpnetsecurity.com/2017/02/17/insecure-car-controlling-android-aps/
Issue
The security on this topic has tended to be overlooked with this area. The smart phone and vehicle applications have tended to be under-researched and studied. This is and continues to be evidenced by this connection and attack points historically being an issue and compromised in relatively many of the manufacturers. Kaspersky Labs elected to test seven of these applications native to the Android platform engineered to interact with the vehicles. These are Android applications, however are coed by the car manufacturers and third party dev op teams.
The sample consisted of seven applications. The target points for this experiment were reverse engineering of the application, if the GUI was adequately secured, if there was an integrity check with the application, and if encryption was applied to the user name and password. The research indicated the application code was not obfuscated, the username and password were not encrypted, there was no application integrity checks, and other insecure features. These applications did not incorporate even the basic security features. The applications and manufacturers were not noted as the researchers did not want these to be targeted by the attackers. This experiment also indicated the systems were open to credential theft.
Analysis
The applications basically controlled access to the vehicle and its functions, acting as a gate. Unfortunately the gate was not locked and the handle easily lifted. A deviant and attacker would be able to gain access to the vehicle’s interior using these insecure features. From here, the attacker would be able to steal the vehicle. As noted this is a rather blatant issue that has been problematic for years with many different manufacturers.
Closing
The vehicle has a great amount of respect for the vehicle. The owner and user do not want the vehicle to be vandalized and stolen. When the owner purchased the vehicle they bargained for, the person was not expecting the connectivity and application to be insecure and open to a form of vandalism. The level of insecurity allows for the vehicle to be attacked from many points. This could have been remediated with better planning or coding.
Resources
Greenberg, A. (2017, February 16). Android phone hacks could unlock millions of cars. Retrieved from https://www.wired.com/2017/02/hacked-android-phones-unlock-millions-cars/
Kuzin, M., & Chebyshev, V. (2017, February 16). Mobile apps and stealing a connected car. Retrieved from https://securelist.com/analysis/publications/77576/mobile-apps-and-stealing-a-connected-car
Zorz, Z. (2017, February 17). Insecure car-controllering android apps are a boon for car thieves. Retrieved from https://www.helpnetsecurity.com/2017/02/17/insecure-car-controlling-android-aps/
Subscribe to:
Posts (Atom)