Google Search

Showing posts with label Systems. Show all posts
Showing posts with label Systems. Show all posts

Sunday, June 8, 2014

Privacy compliance for big data systems automated: Search engine code is moving target that eludes manual audits

Web services companies, such as Facebook, Google and Microsoft, all make promises about how they will use personal information they gather. But ensuring that millions of lines of code in their systems operate in ways consistent with privacy promises is labor-intensive and difficult. A team from Carnegie Mellon University and Microsoft Research, however, has shown these compliance checks can be automated.

The researchers developed a prototype automated system that is now running on the data analytics pipeline of Bing, Microsoft's search engine. According to Saikat Guha, researcher at Microsoft, it's the first time automated privacy compliance analysis has been applied to the production code of an Internet-scale system and is a reflection of Microsoft's commitment to creating the technology necessary to further safeguard the privacy of customers.

Employing a new, lawyer-friendly language to specify privacy policies and using a data inventory to annotate existing programs, the researchers showed that a team of just five people could manage a daily compliance check on millions of lines of code written by several thousand developers.

They presented their research findings at the 35th IEEE Symposium on Security & Privacy, May 18-21, in San Jose, Calif.

"Companies in the United States have a legal obligation to declare how they use personal information they gather and it's also good business to establish a bond of trust with customers," said Anupam Datta, associate professor of computer science and electrical and computer engineering. "But these systems are constantly evolving and their scale can be daunting. The manual methods typically used for checking compliance are labor intensive, yet too often fail to catch all violations of policy."

"Tens of millions of lines of code are already in the pipeline," noted Shayak Sen, a Ph.D. student in computer science who interned at Microsoft Research India and the lead student author on the study. "And during our implementation on Bing, we found that more than 20 percent of the code was changing on a daily basis." At these large scales, automated methods offer the best hope of verifying compliance.

"One reason that gaps exist between policies set by a company's privacy team and the code written by software developers is that the two groups don't speak the same language," Datta said. Lawyers and privacy champions typically have little experience in programming and developers attempting to translate policies into code can get tripped up by ambiguities in the language of the privacy policies.

So the researchers developed a language -- Legalease -- that could be easily learned and used by privacy advocates. It employs allow-deny rules with exceptions, a structure that is found in many privacy policies and laws, such as the Health Insurance Portability and Accountability Act (HIPAA), and is expressive enough to capture the real policies of an industrial-scale system such as Bing.

In preliminary usability testing, a dozen Microsoft employees were given a one-page document explaining Legalease and spent an average of under 5 minutes studying it. They then took an average of less than 15 minutes to encode nine Bing policy clauses regarding how user information can be used. "They were able to perform this task with a high degree of accuracy, which is encouraging," Sen said.

But encoding privacy policies correctly means little if it cannot be applied to large codebases written by large teams of programmers. To solve this dilemma, the researchers leveraged Grok -- a data inventory that annotates existing programs written in languages typically employed by MapReduce-like systems, such as those used by Bing and Google -- for their backend data analytics over user data.

Grok performs this automated annotation by combining information from different sources with varying levels of confidence. For instance, automated pattern-matching to column names can be performed across an entire database, but with low confidence, while annotations by developers have high confidence, but low coverage.

Grok had been developed by Microsoft Research and deployed by Bing for the express purpose of automating privacy compliance checking the previous year, but writing policies for Grok was cumbersome.

"Legalease was the final piece of the automated privacy compliance jigsaw puzzle," Guha said. "Developed over Sen's internship and subsequent collaboration with CMU, Legalease bridged privacy teams with Grok, and through Grok, with the developers."

Datta said automating the process of compliance checks could push the industry to adopt stronger privacy protection policies.

"Sometimes, companies want to make their policies stronger, but hesitate because they are not sure they can ensure compliance in these large systems," he explained, noting that online privacy policy compliance is enforced in the United States by the Federal Trade Commission.

The research team included Sriram K. Rajamani of Microsoft Research in Bangalore, India; Janice Tsai of Microsoft Research, Redmond, and Jeannette Wing, corporate vice president of Microsoft Research and former head of CMU's Computer Science Department.

This research was supported, in part, by the Air Force Office of Scientific Research and the National Science Foundation.


View the original article here

Thursday, December 19, 2013

NSA's XKeyscore is a global dragnet for vulnerable systems

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

XKeyscoreXKeyscore doesn't just turn somebody's internet life inside out. It's also a bloodhound for sniffing out vulnerable systems.

A training slide on page 24 of the National Security Agency's 2008 presentation on the program, as revealed on Wednesday by The Guardian (via Edward Snowden), states it quite baldly:

Show me all the exploitable machines in country X Fingerprints from TAO [Ed. Note: Tailored Access Operations, the NSA organisation that hacks the networks of foreign governments and organizations] are loaded into XKEYSCORE'S application/fingerprintID engineData is tagged and databasedNo strong-selectorComplex boolean tasking and regular expressions required

According to Ars Technica's Sean Gallagher, the vulnerability "fingerprints" are added to serve as a filtering criteria for XKeyscore's application engines, comprised of "a worldwide distributed cluster of Linux servers attached to the NSA's Internet backbone tap points."

This turns XKeyscore into a passive port scanner, Gallagher writes, which can be used to search for network behavior on systems that match the NSA TAO's profiles for exploits or for systems already exploited by malware that the TAO can then take advantage of.

He explains how this could give the NSA a toehold of surveillance in countries such as Iran or China:

This could allow the NSA to search broadly for systems within countries such as China or Iran by watching for the network traffic that comes from them through national firewalls, at which point the NSA could exploit those machines to have a presence within those networks.

The slides also explain how XKeyscore can track encrypted VPN (Virtual Private Network) sessions and their participants, can capture metadata on who's using PGP encryption in email or who's encrypting Word documents, which can later be decrypted.

XKeyscore keeps all trapped Internet traffic for three days, but metadata is kept for up to 30 days.

That month gives the NSA time to trace the identity of those who created the documents its analysts intercept.

As the slides imply, this enables XKeyscore the unique ability of scouring traffic that hasn't yet been targeted for monitoring.

"No other system performs this on raw unselected bulk traffic," they state.

XKeyscore's nature was disputed when it was first revealed.

What is XKeyscore, exactly?

Is it a tool that can scour all things internet for surveillance purposes, or is it merely a database search tool plunked on top of databases full of already-captured data from other surveillance sources, as maintained by US journalist Marc Ambinder?

It sure does sound like a surveillance tool, going by the NSA's own description.

According to the slides published by The Guardian, XKeyscore is:

DNI [ed.: Digital Network Intelligence] Exploitation System/Analytic FrameworkPerforms strong (e.g. email) and soft (content) selectionProvides real-time target activity (tipping)"Rolling Buffer" of ~3 days of ALL unfiltered data seen by XKEYSCORE: Stores full-take data at the collection site—indexed by meta-dataProvides a series of viewers for common data typesFederated Query system—one query scans all sites Performing full-take allows analysts to find targets that were previously unknown by mining the meta-data

Has The Guardian mischaracterized XKeyscore as a top-secret, extraordinarily powerful surveillance tool?

I'm trying to keep my mind open, but it's hard to dismiss The Guardian's reporting, and it's hard to deem Edward Snowden's depiction of the NSA's activities as "hyperbolic," as some have deemed them, given the descriptions in these slides.

I'm no programmer, but when somebody calls a program an "exploitation system" that can be used "to find targets that were previously unknown by mining the meta-data," that sure does sound like a surveillance tool to me.

A frighteningly powerful one, at that.

Follow @LisaVaas

Follow @NakedSecurity

View the original article here

Friday, January 11, 2013

Hacker attack siphons off $150,000 in teacher salaries from payroll systems

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Keyboard in darkness. Image from ShutterstockHackers used the American Thanksgiving holiday to launch a crafty attack against a local school district in the state of Wisconsin, compromising a direct deposit system, and stealing $150,000 intended for teachers.

Administrators in the Stanley-Boyd school district in the western part of Wisconsin were alerted to the attack by their bank on November 21, according to a report in the Chippewa Herald.

According to the newspaper, the attackers compromised the district's network and altered its direct deposit file, supplanting employee bank account information with accounts belonging to the attackers.

AnchorBank, based in Madison, Wisconsin, noticed the unusual activity and alerted the district. The district has notified the FBI, which is investigating.

In the meantime, AnchorBank said it had been able to retrieve a portion of the stolen payroll as of November 27, and believed it could recover most of the lost funds.

Hacking school districts isn't about changing grades "War Games"-style.

(Though that still happens, too!) .

Rather, school districts and municipalities are a prime target for cybercriminal gangs, many based outside the United States.

Hackers are attracted to the small towns because they often are short on IT security expertise, but have easy access to cash through bank accounts and lines of credit. Beyond that, the decentralized nature of many municipal operations can make detection difficult.

In just the latest incident, in October, the town of Burlington, Washington, disclosed that hackers had compromised a number of town systems used to operate an online utility billing system and stolen $400,000 from a city bank account.

Follow @paulfroberts
Follow @NakedSecurity

Keyboard image from Shutterstock.


View the original article here

Sunday, November 4, 2012

Chinese hackers linked to breach of control systems used in electric grids

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

electricity_170Attackers breached Telvent's network, the company has informed its customers in a letter. Telvent is the maker of an industrial control system that remotely controls smart grid networks used in portions of the electric grid.

Telvent told its customers that on Sept. 10, it learned that hackers had breached its internal firewall and security systems, implanted malicious software, and stolen project files.

According to
Chinese Hackers Blamed for Intrusion at Energy Industry Giant Telvent" href="http://krebsonsecurity.com/2012/09/chinese-hackers-blamed-for-intrusion-at-energy-industry-giant-telvent/" rel="nofollow">KrebsOnSecurity, which first reported the breach, the project files concerned Telvent's
Standardized, centralized SCADA solutions from Telvent" href="http://www.telvent.com/en/business_areas/smart_grid/solutions_overview/smart_grid/smart_operations/oasys-scada.cfm" rel="nofollow">OASyS SCADA product, which offers energy firms a bridge between older technology and advanced smart grid technologies.

Telvent, which is owned by Schneider Electric, told customers that the attack spans operations in the US, Canada and Spain.

Experts detected digital fingerprints implicating a Chinese hacking group that has been tied to cyber-espionage campaigns against Western interests.

Telvent_logo

KrebsOnSecurity cited Joe Stewart, director of malware research at Dell SecureWorks, who said that website and malware names mentioned in a more recent letter from Telvent can be traced to a Chinese hacking team known as the "Comment Group."

That group, often referred to as the Comment group, has been under investigation by US intelligence for years.

Researchers told Bloomberg that during two months of monitoring last year, targeted companies spanned a vast scale as data "bled from one victim to the next":

...from oilfield services leader Halliburton Co. (HAL) to Washington law firm Wiley Rein LLP; from a Canadian magistrate involved in a sensitive China extradition case to Kolkata-based tobacco and technology conglomerate ITC Ltd. (ITC)

A loose-knit group of some 30 North American private security researchers tracking the group have called the Comment Group one of the biggest and busiest hacking groups in China.

Bloomberg quoted Shawn Henry, former executive assistant director of the FBI in charge of the agency’s cyber division, who said that typical cybersecurity headlines about data breaches scarcely hint at the scope of the group's activities:

What the general public hears about — stolen credit card numbers, somebody hacked LinkedIn (LNKD) — that’s the tip of the iceberg, the unclassified stuff. … I’ve been circling the iceberg in a submarine. This is the biggest vacuuming up of U.S. proprietary data that we’ve ever seen. It’s a machine.

Evidence indicates that at least 20 organizations have been harvested for data, many of whose secrets could give China a leg up on its path to becoming the world’s largest economy.

Bloomberg cited unnamed security experts who said that the breaches have sprung data leaks in major oil companies, who've lost seismic maps charting oil reserves, while patent law firms have been squeezed for clients' trade secrets and investment banks have been targeted for market analysis regarding global ventures of state-owned companies.

Telvent said that investigations are still under way, but it's taken the precaution of severing data links between clients and the affected portions of its internal networks.

The company also said that it hasn't yet found evidence that the attackers had been able to compromise customers' systems:

Although we do not have any reason to believe that the intruder(s) acquired any information that would enable them to gain access to a customer system or that any of the compromised computers have been connected to a customer system, as a further precautionary measure, we indefinitely terminated any customer system access by Telvent.

Telvent gave me this statement:

Telvent is aware of a security breach of its corporate network that has affected some customer files. Customers have been informed and are taking recommended actions, with the support of Telvent teams. Telvent is actively working with law enforcement, security specialists and its affected customers to ensure the breach has been contained.

Meanwhile, the Obama adminstration and Congress have grown increasingly vocal about Chinese and Russian cyber espionage and attacks, with the White House close to completing the first draft of a cybersecurity executive order designed to bring about stronger cyber security around the nation's water, electrical and transportation systems.

It's a reasonable thing to call for stronger protection around vital infrastructure.

But as Reuters pointed out in a recent report on what one top US cybersecurity official called "reckless" cyber behavior from nation states, the US's right to complain about other nations' cyber warfare might be questionable, given what is by now a widespread belief that the US and Israel were behind Stuxnet.

Follow @LisaVaas
Follow @nakedsecurity

electricity images courtesy of Shutterstock


View the original article here

Saturday, March 3, 2012

Sony, Microsoft Battle Hackers Over Right to 'Jailbreak' Video Game Systems

Another high-tech and high-stakes copyright battle is brewing—this time between video game console manufacturers such as Microsoft and Sony and the hackers who like to tinker with the devices' inner workings, allowing them to perform new and socially responsible functions, but also perhaps to play pirated media and games.

Microsoft's Xbox 360 and Sony's Playstation 3 pack an exceptional amount of graphics and computing power at a relatively low price. As tech-savvy consumers and scientists realized this, they began to circumvent the "walled garden" the companies created, using the consoles as cheap computers or number-crunching machines.

University professors, amateur hobbyists, and big-time scientists realized the potential of the Playstation 3's computing power. The United States Air Force networked 1,700 PS3's to form one of the most powerful supercomputers in the world. A researcher at the University of Massachusetts used a grid of eight PS3s to simulate gravitational waves. Thousands of amateur game makers began to create "homebrewed" software that could be played on modified Playstation or Xbox systems. Thousands of pirates modified their systems to play "backup" copies of commercial games.

Nearly all of those nonprescribed uses of video game consoles are illegal, according to the Digital Millennium Copyright Act, an expansive law criminalizing digital piracy and the development or modification of devices to allow machines to play pirated media (the USAF has a special agreement with Sony).

[Love and Warcraft: Spouses Being Pushed Aside For Video Games]

A new push by amateur hackers and digital rights activist groups such as the Electronic Frontier Foundation, or EFF, could make "jailbreaking" video game consoles legal under a similar exemption afforded consumers who jailbreak iPhones (a process that allows users to turn their phones into wireless hotspots, install unlicensed software, and achieve a level of customization Apple doesn't provide). The copyright office is taking public input on the subject until Friday, and will likely make a decision soon after.

Andrew Huang, who wrote about modifying an Xbox while studying electrical engineering at MIT and later turned it into a book, argues that jailbreaking allows users to "gain full administrative access" to a video game console to "innovate and take advantage of the device's full potential."

His book includes more than 250 pages detailing how to reverse engineer and modify an Xbox to run homebrewed software developed by amateurs, add USB ports, exploit security holes, and run alternative operating systems such as Linux.

[Sony Says it Has Sold 1.2 Million Playstation Vitas]

The EFF argues the exemption is needed to allow consumers to "use lawfully obtained software of their own choosing," even if it isn't licensed by Microsoft or Sony.

Unsurprisingly, Microsoft and Sony are pushing back hard. In a statement to the U.S. Copyright Office, Sony said jailbreaking "will enable--indeed, may often be intended to facilitate--the unauthorized copying and commercial piracy of a large number of valuable copyrighted works."

It hasn't always been this way. When the Playstation 3 was released in 2006, Sony touted it as an inexpensive computer replacement, and even included a feature that allowed users to run the Linux operating system.

Phil Harrison, then a vice president at Sony, said at the time that the company hoped "that the PS3 will be the place where our users play, watch films, browse the Web … the Playstation 3 is a computer. We do not need the PC."

In 2010, hackers found a vulnerability in the company's sanctioned Linux environment that allowed users to play pirated games. It appears that hack soured Sony on the idea of the Playstation-as-computer. It shut down the Linux environment, locking users out from playing homemade games and researchers from modifying the PS3 in the process. In its statement to the copyright office, Sony had a message for homebrew gamers and researchers: Go elsewhere.


View the original article here