Google Search

Showing posts with label approach. Show all posts
Showing posts with label approach. Show all posts

Wednesday, June 11, 2014

Finding the hidden zombie in your network: Statistical approach to unraveling computer botnets

How do you detect a "botnet," a network of computers infected with malware -so-called zombies -- that allow a third party to take control of those machines? The answer may lie in a statistical tool first published in 1966 and brought into the digital age researchers writing this month in the International Journal of Electronic Security and Digital Forensics.

Millions of computers across the globe are infected with malware, despite the best efforts of public awareness campaigns about phishing attacks and antivirus software. Much of the infection is directed towards allowing a third party to take control of a given machine or indeed a network of machines and exploiting them unbeknownst the legitimate users in malicious and criminal activity. Security and software companies do monitor internet activity and there have been many well-publicized successes in destroying such botnets. However, malware writers are always developing new tools and techniques that allow them to infect unprotected computers and rebuild botnets.

Botnets are widely used in organized crime to attempt breaches on security systems by mounting distributed denial of service (dDOS) attacks, among other techniques, on corporate, banking and government systems. Such attacks can open up "backdoors" into a private computer network that lets the botnet controller access proprietary and other sensitive information, passwords or even voting systems. Botnets have also been used for simply malicious purposes to force websites and other services offline, occasionally in an act of protest or rebellion.

Now, R. Anitha and colleagues at PSG College of Technology, Coimbatore, India, have turned to a statistical tool known as the hidden semi-Markov model (HsMM) to help them develop monitoring software that can detect the telltale signs of botnet activity on a computer and so disable the offending malware. In probability theory and statistics, a Markov process is one in which someone can predict the next state of a process based on its current state without knowing the full history of the process. An example in gambling would be that if you have chip now and the odds of winning or losing on the next bet are even then we can predict without knowing how many chips you had earlier that you will either have none or two after the next bet.

A hidden-Markov model would thus include variables of which the observer has no sight but can infer and so predict an outcome. Predicting whether it rained on a given day based on whether a fair-weather-only walker was out on a given day without you having a weather report for their area involves a hidden-Markov process. A hidden semi-Markov model then involves a process of this sort but where the time-elapsed into the current state affects the prediction. For example, one might predict the rainfall pattern based on how long it is since our fair-weather walk last ventured out.

The team has applied the statistical logic of the hidden semi-Markov model to forecast the characteristics of internet activity on a given computer suspected of being a "zombie computer" in a botnet based on management information base (MIB) variables. These variables are the components used to control the flow of data packets in and out of the computer via the internet protocol. Their approach can model the "normal" behavior and then highlight botnet activity as being a deviation from the normal without the specific variables that are altered by the malware being in plain sight.

The team points out that botnet and malware developers have focused recently on web-based, http, type activity, which is easier to disguise among the myriad packets of data moving to and fro across a network and in and out of a particular computer. Their tests on a small zombie computer network shows that the hidden semi-Markov model they have developed as a lightweight and real-time detection system can see through this disguise easily. If implemented widely such as system could lock down this kind of botnet very quickly and slow the assimilation of zombie computers by criminals and others with malicious intent.


View the original article here

Saturday, August 25, 2012

Online Piracy: Challenging the 'three strikes' approach

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

The 'graduated response' strategy to stopping illegal online filesharing has been replicated in countries around the world from South Korea to New Zealand, France and the UK.

Copyright. Image from Shutterstock

Whilst the sanctions and legal process differ, the general 'three strikes or you're out' approach works by sending warnings to customers about copyright infringement allegations against them, telling them to stop or face the consequences.

These laws are often controversial, and are frequently seen as the result of extensive government lobbying by the film and music industry to protect their out-dated business models.

Nevertheless, the proponents argue they lose vast sums of money from piracy which diminishes the economic growth of creative industries, thus making such laws necessary.

The controversy often lies in the draconian and disproportionate punishments, which go far beyond a casual slap on the wrist.

In New Zealand, for example, a presumption of guilt lies on the alleged infringer, and if they can't disprove the charges, they can face fines up to NZ $15,000 or a maximum six month internet disconnection for repeat infringement.

In France, the law allows a judge to order internet disconnection for up to one year, or alternatively a €1500 fine.

It is this well-established French "Hadopi" system that three years on has now been called into question this week by the French Culture Minister, Aurélie Filippetti.

Aurélie FilippettiAurélie Filippetti condemns the regulator as a waste of money, citing its failure to develop alternative legal download services, and questions the proportionality of disconnecting repeat offenders from the internet.

It costs a whopping €12 million per year for its 60 officers who send around 1 million emails annually.

Although nobody has actually been disconnected under the law, 314 cases have gone through their warnings and then referred for prosecution.

Hadopi is currently under broader review, and its future and funding are uncertain as Filippetti feels its utility has not been proven.

So, what warning might the Hadopi experience provide for other younger graduated response policies, particularly for the UK?

The UK government has recently restarted the push for enforcement of the Digital Economy Act (DEA). Whilst it was rushed onto the statute books back in 2010, enforcement has repeatedly been postponed.

Skull. Image from ShutterstockFollowing the failure of an appeal against the DEA by Talk Talk and BT in March this year the regulator Ofcom reopened their consultation on the draft operational DEA code last month.

The new text states that as of 2014 copyright owners who identify sources of illegal downloading can report this information to the relevant ISPs.

From there, the ISP tracks down the infringing subscriber and posts them notification letters warning them to stop illegally downloading content.

If the subscriber ignores the warnings and receives three of these letters within 12 months, their details are added to an anonymised "Copyright Infringement List".

Once on this list, copyright owners can then seek a court order demanding the ISP hand over the information needed to begin legal action against the infringer.

Whilst the threat of litigation is clearly a pretty big incentive to stop illegally downloading, punishment without changing the underlying reason for such behaviour can only do so much.

As noted above, Hadopi has been criticised for not developing legal alternatives. The Ofcom Code however pushes for directing of users to legal, licensed services, and stresses the need for development of attractive online content services.

IPO reportThis reflects recommendations for reform made in last year's UK Government-commissioned "Digital Opportunity: A review of Intellectual Property and Growth" report, where Professor Ian Hargreaves noted, "Emphasising enforcement as an alternative to improved digital licensing and modernised copyright law is the wrong approach. Action is needed on all fronts. "

He continued, "The role for Government is to facilitate the provision of readily available legitimate digital content, to reshape copyright law where it is out of touch and to support this with effective measures to educate consumers and to enforce the law."

It seems that heavy-handed enforcement and pointing infringers to a few overpriced legal content access services won't be enough to truly address piracy. The content providers who only rely on the big stick of demonising and chasing illegal downloaders need to do more to find their elusive carrot.

Until there are enough innovative, responsive business models allowing quality, low cost access to legal content, (such as licensed streaming) it is difficult to see how copyright owners can realistically compete with the alternative of free, on demand pirated content.

Follow @mooseabyte

Copyright and Skull icon images from Shutterstock.


View the original article here

Tuesday, August 23, 2011

Lateral approach to protective hacking - Stuff.co.nz

CLAIRE ROGERS LEGITIMATE HACKERS: Lateral Security co-founders Ratu Mason, left, and Nick von Dadelszen test website security. CRAIG SIMCOX/The Dominion Post

LEGITIMATE HACKERS: Lateral Security co-founders Ratu Mason, left, and Nick von Dadelszen test website security.


Hacking into the computer systems of banks and government departments is usually the preserve of cyber criminals, but Ratu Mason and Nick von Dadelszen have turned it into a flourishing – and legitimate – business.


They own Wellington company Lateral Security, which tests the websites, databases, mobiles and email systems of large corporate and government clients for vulnerabilities, Mason says.


"We test all the communication channels that go in and out of a business that are internet based. Clients generally do regular testing and if they're rolling out a new system or service, they want to make sure it's OK before it goes live," he says.


The company also responds to "ambulance calls" to help organisations investigate an attack, von Dadelszen says.


"They might not know where they have been hacked, how it happened and how far someone got in."


Hacking attacks are becoming more frequent, he says, and recent high-profile intrusions include the Sony PlayStation network hack, an attack on Melbourne online services company DistributeIT, and the disabling of the New Zealand Parliament website by hacking group Anonymous.


Mason says the increase in attacks is partly because there is more technology, and people are more reliant on it for work and personal matters.


"You've got so many more mobile devices these days and they all have high-speed internet access, and the processing power of computers has gone up so much you can do more continuous types of attacks than you would have been able to do before."


The company's eight staff use the same methods as criminal hackers to try to breach systems, and are constantly researching and upskilling on the techniques, says von Dadelszen.


He found he had a knack for security after his university flatmate challenged him to hack into his computer.


Lateral Security has clearance to do security testing work for governments in Australia, Canada, the United States and in Britain, where it has set up a "virtual office" to help clients, Mason says.


It has recently opened an Auckland office, with three staff, and plans to hire a further three.


"Our biggest challenge in this industry is finding skilled people and making them realise that you can actually make a legitimate living out of doing what we do."


It plans to set up an office in Hong Kong, Singapore or China.


"They are the major growth markets and they are becoming major financial hubs in the world, and that means they will have more to protect."


It continually stresses to clients the need to back-up systems and data, Mason says.


"We might be engaged to do a week's worth of work and find a whole bunch of things. But the real nasty guys out there have all the time in the world. You always need to be prepared that, at some stage, you may get hacked."


Von Dadelszen says his job description is usually a good conversation starter.


"The first question I always get is, `Can you put money in my bank account?"'


- BusinessDay.co.nz


View the original article here