Google Search

Showing posts with label cyber. Show all posts
Showing posts with label cyber. Show all posts

Tuesday, May 27, 2014

Platform would protect smartphones from cyber criminals

Criminals don't have to pick your pocket to get what they want out of your mobile. But a certifiably secure operating platform is being developed by Swedish researchers so that consumers can be confident that their mobile data is safe.

Market analysts expect the next decade to see a significant expansion in the numbers of connected devices and machines.

But increased connectivity also presents an opportunity for criminals. Mads Dam, an expert in computer security at Stockholm's KTH Royal Institute of Technology, says that devices and modules will be exposed to increasingly sophisticated attacks by cyber criminals.

"People are going to place even higher value on products with verifiable security claims," says Dam, who is Professor of Teleinformatics at KTH's School of Computer Science and Communication.

While compact in size, mobile phones pose a huge security challenge, Dam says. "Android, for example, has more than 10 million lines of code and is executing on a computing platform with one billion transistors.

"So it's not surprising that securing this kind of system is difficult," Dam says. "The good news is that an end-to-end security guarantee is within reach."

Dam and his colleagues aim to publish a certifiably secure, trusted execution platform for operating systems. The idea is to outwit malware and other attacks on a device with a layer of software called a "hypervisor," which is designed to secure the interaction between the operating system (OS) and the hardware.

"If the operating system asks for the camera to be turned on, the hypervisor can step in and verify whether that is really what the user wants," he says. "Or if the operating system wants to access a piece of memory that normally should be regarded as secure, it could step in and allow, or disallow, the request."

In fact, Dam says, a hypervisor-based solution could completely isolate different apps from each other, to create truly tamper-proof applications, for instance for banking or communication.

Such a platform could be made much smaller than the OS itself, he says. "We're talking about a factor of 1,000 to 10,000, which is sufficient to create mathematical models that can analyse the security of interaction between the OS and the hardware so well that we can formally guarantee the security of an operating system like Linux."

And it's not just mobile users that will benefit. In addition to mobile communications networks, the platform would be applicable in a wide range of areas including control systems for manufacturing plants, power stations, utilities and infrastructure. Other uses would be in vehicles, avionics and medical systems, cloud application platforms and also for devices in the internet of things.

The project partners, which include the Swedish Institute of Computer Science (SICS), propose publishing key components of the hypervisor as open source, in order to increase trust and allow de facto industry standardization of the security platform.

Dam says it will require more than a secure execution platform to secure devices from end-to-end, that is, from the user interface through the software stack, down to bits of silicon and back. Hardware and application platforms will have to be validated too. But the KTH team has made great progress during the last decade on tracing security from the application and user interface to the execution platform and back, he says, and the hypervisor will be a vital tool to achieve this.

"Soon we will be able to engage industry and organisations with serious security concerns, like banks, public organisations, defence and providers, and develop this space."

Cite This Page:

KTH The Royal Institute of Technology. "Platform would protect smartphones from cyber criminals." ScienceDaily. ScienceDaily, 5 March 2014. .KTH The Royal Institute of Technology. (2014, March 5). Platform would protect smartphones from cyber criminals. ScienceDaily. Retrieved May 5, 2014 from www.sciencedaily.com/releases/2014/03/140305125102.htmKTH The Royal Institute of Technology. "Platform would protect smartphones from cyber criminals." ScienceDaily. www.sciencedaily.com/releases/2014/03/140305125102.htm (accessed May 5, 2014).

View the original article here

Monday, December 23, 2013

Will insurance firms be the big winners in the struggle for cyber security?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Insurance button. Image courtesy of ShutterstockA blog post by one of US President Obama's top cybersecurity advisers has sparked a debate on the importance of insurance in mitigating the threat posed by digital dangers to the world's businesses and government agencies.

The insurance world is a massive moneyspinner, with global premiums of over $4.6 trillion paid out last year.

Insurers are always on the lookout for new dangers to insure us against, and it seems like cybercrime, hacking and compromises of business networks are considered a booming sector, ripe for expansion and exploitation.

Michael Daniel, a special assistant to Obama and cybersecurity coordinator, posted to a Whitehouse.gov blog earlier this week discussing the Cybersecurity Framework being put together by the US government.

The aim of the Framework is to encourage and enable companies, especially those providing critical infrastructure services in the US, to ensure they keep their computers and networks safe from compromise and infiltration.

With input from various teams working on the framework, including Homeland Security and the Treasury and Commerce Departments, the article suggests a list of eight methods to help encourage firms to adopt the proposed framework.

Several of these measures revolve around simplified regulation, tax breaks, government grants, research support, and preferential contracts.

But top of the list is the suggestion that the insurance industry should be encouraged to get involved:

Agencies suggested that the insurance industry be engaged when developing the standards, procedures, and other measures that comprise the Framework and the Program.

The goal of this collaboration would be to build underwriting practices that promote the adoption of cyber risk-reducing measures and risk-based pricing and foster a competitive cyber insurance market.

The cybersecurity insurance market is relatively new and undeveloped, according to a study last year from consulants Cap Gemini. Although we started seeing insurance against infection thrown in with some AV products several years ago, this was little more than a gimmick and never really took off.

The involvement of the big insurance players, covering big companies against potentially massive losses, is steadily transforming it into a major business though. It's already raking in an estimated $1.3 billion per year in the US, with the rest of the world lagging some way behind.

Firms in Europe are slowly starting to expand into the field though, more than a year after the EU debated making cyber-insurance mandatory in some fields.

In Australia the market has been described as "promising to be a new boomlet", with insurance experts sharing tips with each other on how to promote their new products:

What is cyber crime really costing Australia and the rest of the world? Use these jaw-dropping stats if your clients need convincing of the need for cover against cyber crime.

So, assuming you're not an insurance salesman and haven't invested heavily in insurance company stocks, how will this benefit you?

First of all, there should be a major improvement in the stats. Analysis of the size of the cybercrime threat, the numbers of people it effects and the amounts of money involved tends to be rather hazy. It's a shadowy business of course, and pinning down its exact scope is complex and difficult.

Insurers love stats though. They need lots of data to calculate the odds on which to base their premiums.

If you want to insure yourself against getting your beard snagged in the wing mirror of a passing bus, you probably can, because they have detailed tables of historical data on how often that sort of thing happens, going back years (your premium will probably depend on the length and luxuriousness of the beard, and how often you hang out on bus routes).

Cybercrime. Image courtesy of ShutterstockFor cybercrime though, the stats are few on the ground, with little history and not much verification.

We routinely see studies and reports trying to put figures to various things, such as how many firms have been hit by cyber attacks, the amount lost to cybercrime each year (135,000 Euros per incident in Ireland, apparently, but $5.4 million in the US), or how those who should be measuring this stuff are simply giving the whole thing up as a lost cause.

Attempts to reckon up the cost of all cybercrime at national or global levels tend to be fairly vague, hyperbole-ridden and even contradictory of previous guesses, with methodologies often sloppy and open to criticism.

So, as money starts to flood into the insurance firms, hopefully some of it will trickle back out into funding more comprehensive and scientific research into measuring the scale and impact of the threat.

The more we know about the size of the danger, and the more detail we have about what's hitting who, where, and how hard, the easier it should be to target efforts to combat it.

There should also be more work done by businesses estimating their own risks from cybercrime, reckoned by some to be the biggest threat the world's businesses and governments face. The process of risk appraisal should give them some ideas of what needs to be done to cover the holes.

Secondly, there should be financial pressure on businesses to improve their defences. Just as house insurance is cheaper if you have an alarm system and high-quality locks, so your cyber insurance premiums will go down if you can prove you have top-notch security processes and technologies protecting your networks and data.

In the long term, that should benefit everyone, as companies will be encouraged to invest in security so they can save money on insurance. Breaches and data leaks will go down, our data will be kept out of the hands of the bad guys, and we'll be able to carry on our digital lives in blissful safety and privacy.

That's the theory at least. It could be, of course, that some firms will start slacking on the security front, feeling they don't need to bother too much as they'll be covered financially if there's a problem.

This would mean more hassle for us, as our data is left lying around on under-protected servers for anyone and everyone to harvest and exploit.

Whatever happens, it seems clear that as long as they can keep their premiums bigger than their payouts (a pretty safe bet), the one big winner will be the insurance firms.

Follow @VirusBtn
Follow @NakedSecurity

Image of insurance button and cybercrime courtesy of Shutterstock.


View the original article here

Tuesday, October 29, 2013

Cyber experts say calling out China may be working

SINGAPORE (AP) -- After years of quiet and largely unsuccessful diplomacy, the U.S. has brought its persistent computer-hacking problems with China into the open, delivering a steady drumbeat of reports accusing Beijing's government and military of computer-based attacks against America.

Officials say the new strategy may be having some impact.

In recent private meetings with U.S. officials, Chinese leaders have moved past their once-intractable denials of cyber espionage and are acknowledging there is a problem. And while there have been no actual admissions of guilt, officials say the Chinese seem more open to trying to work with the U.S. to address the problems.

"By going public the administration has made a lot of progress," said James Lewis, a cybersecurity expert at the Center for Strategic and International Studies who has met with Chinese leaders on cyber issues.

But it will likely be a long and bumpy road, as any number of regional disputes and tensions could suddenly stir dissent and stall progress.

On Wednesday, China's Internet security chief told state media that Beijing has amassed large amounts of data about U.S.-based hacking attacks against China but refrains from blaming the White House or the Pentagon because it would be irresponsible.

The state-run English-language China Daily reported that Huang Chengqing, director of the government's Internet emergency response agency, said Beijing and Washington should cooperate rather than confront each other in the fight against cyberattacks. Huang also called for mutual trust.

President Barack Obama is expected to bring up the issue when he meets with China's new president, Xi Jinping, in Southern California later this week. The officials from the two nations have agreed to meet and discuss the issue in a new working group that Secretary of State John Kerry announced in April. Obama's Cabinet members and staff have been laying the groundwork for those discussions.

Standing on the stage at the Shangri-La Dialogue security conference last weekend, Defense Secretary Chuck Hagel became the latest U.S. official to openly accuse the Chinese government of cyber espionage — as members of Beijing's delegation sat in the audience in front of him. The U.S., he said, "has expressed our concerns about the growing threat of cyber intrusions, some of which appear to be tied to the Chinese government and military."

But speaking to reporters traveling with him to the meeting in this island nation in China's backyard, Hagel said it's important to use both public diplomacy and private engagements when dealing with other nations such as China on cyber problems.

"I've rarely seen that public engagement resolves a problem, but it's important," he said, adding that governments have the responsibility to keep their people informed about such issues.

The hacking issue also featured prominently over two days of meetings between the U.S. Chamber of Commerce and a leading Chinese trade think tank in Beijing.

"This is arguably the single most consequential issue that is serving to erode trust in the relationship," said Jeremie Waterman, the chamber's executive director for greater China. "Over time, it could undermine business support for U.S.-China relations."

According to Lewis and other defense officials familiar with the issue, China's willingness to engage in talks with the U.S. about the problem — even without admitting to some of the breaches — is a step in the right direction.

Cybersecurity experts say China-based instances of cyber intrusions into U.S. agencies and programs — including defense contractors and military weapons systems — have been going on since the late 1990s. And they went along largely unfettered for as much as a decade.

A recent Pentagon report compiled by the Defense Science Board laid out what it called a partial list of 37 programs that were breached in computer-based attacks, including the Terminal High Altitude Area Defense weapon, a land-based missile defense system that was recently deployed to Guam to help counter the North Korean threat. Other programs whose systems were breached include the F-35 Joint Strike Fighter, the F-22 Raptor fighter jet and the hybrid MV-22 Osprey, which can take off and land like a helicopter and fly like an airplane.

The report also listed 29 broader defense technologies that have been compromised, including drone video systems and high-tech avionics. The information was gathered more than two years ago, so some of the data are dated and a few of the breaches — such as the F-35 — had already become public.

According to U.S. officials and cyber experts, China hackers use gaps in software or scams that target users' email systems to infiltrate government and corporate networks. They are then often able to view or steal files or use those computers to move through the network accessing other data.

Chinese officials have long denied any role in cyberattacks and insisted that the law forbids hacking and that their military has no role in it. They have also asserted that they, too, are often the victim.

Cyber experts say some of the breaches that emanate from Internet locations in China may be the product of patriotic hackers who are not working at the behest of Beijing's government or military but in independent support of it.

The Chinese government's control of the Internet, however, suggests that those hackers are likely operating with at least the knowledge of authorities who may choose to look the other way.

U.S. officials have quietly grumbled about the problem for several years but steadfastly refused to speak publicly about it. As the intrusions grew in number and sophistication, affecting an increasing number of government agencies, private companies and citizens, alarmed authorities began to rethink that strategy.

They were pressed on by cybersecurity experts — including prominent former government officials — who argued that using cyberattacks to steal intellectual property, weapons and financial data and other corporate secrets brought great gain at very little cost to the hackers. The U.S. government, they said, had to make it clear to the Chinese that continued bad behavior would trigger consequences.

In November 2011, U.S. intelligence officials for the first time publicly accused China and Russia of systematically stealing American high-tech data for economic gain.

That was followed by specific warnings about Chinese cyberattacks in the last two annual Pentagon reports on China's military power. And in February, the Virginia-based cybersecurity firm Mandiant laid out a detailed report directly linking a secret Chinese military unit in Shanghai to years of cyberattacks against U.S. companies. After analyzing breaches that compromised more than 140 companies, Mandiant concluded that they can be linked to a unit that experts believe is part of the People's Liberation Army's cyber command.

The change in tone from the Chinese leaders came through during recent meetings with Gen. Martin Dempsey, chairman of the Joint Chiefs of Staff, and has continued, according to officials and experts familiar with more recent discussions with Chinese leaders.

Still, experts say that progress with the Chinese will still be slow and that it's naive to think the cyberattacks will stop.

"This will take continuous pressure for a number of years," said Lewis. "We will need both carrots and sticks, and the question is when do you use them."


View the original article here

Friday, September 27, 2013

Cyber security in US power system suffering from reactive, self-policed rules

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Power failureNorth America’s electricity generation and distribution network is a vital piece of infrastructure, and is rightly considered a major potential target for attack from terrorists, activists or corporate snoops.

Its cyber defences seem to be inadequate though, with regulation mainly self-imposed and minimally enforced. Policy in the area also appears to focus on reacting to emerging threats, rather than setting up proactive barriers against potential problems.

A major report on the subject has been produced by the offices of two US Congressmen, Ed Markey (D-Mass.) and Henry A. Waxman (D-Calif.). They found that most power companies were under heavy cyber attack, but that few had done more than the minimum to implement protective processes.

A run-down of the report’s major findings can be found at The Register – there are plenty of juicy, scary stats based on responses to a survey sent to over 150 organisations.

The main point the study’s authors are trying to make is that there are many rules in place for how networks and systems should be protected, some mandatory and some optional, and not everyone’s applying all the mandatory steps yet, let alone the optional ones.

The rules are laid out by a non-profit body called NERC, the North American Electric Reliability Corporation. This is a cross-industry group focussed on keeping America’s lights on, generating standards and best practices for electricity generation and infrastructure. They’re overseen by FERC, the Federal Energy Regulatory Commission.

To create a new rule for the power companies to follow, a NERC committee (of which there seem to be many) will draft a guideline, which must then be approved by the membership – which is the power companies. If approved, the guideline is then passed to FERC for further approval before becoming an enforceable standard.

Obviously, this is a slow process, with any rule which is thought likely to cause difficulties to the people it’s supposed to be imposed upon likely to be vetoed, by those very same people.

The complexities of the system, and the highly distributed nature of the US power infrastructure, make it hard to monitor and enforce compliance, even when guidelines do become rules.

NERC publicationNERC produce some epic documents – their full run-down of standards makes for an eye-watering 1800-page read.

The (relatively) juicy bit concerning cyber security is section CIP-007, about a quarter of the way down.

Just keeping up with the latest tweaks and additions must be a tough task, let alone trying to apply or enforce them.

Even if the standard creation process can be sped up and made more enforceable, as the report’s authors are urgently suggesting, there’s another problem here.

The emphasis seems to be heavily on responding to threats – how did people respond to 9/11, what have people done in the wake of Stuxnet, what was their reaction to Aurora.

They need to be thinking much more proactively, predicting new attack vectors and implementing protection against new vulnerabilities before they are discovered, let alone put to use by the bad guys.

At least some people at NERC are thinking along the right lines, with another detailed report, released last year by their Cyber Attack Task Force, emphasising the importance of attack trees and other predictive approaches.

What seems to be needed here is a combination of the two vectors, with carefully considered generally defensive strategies combined with fast responses to new, unforeseen vulnerabilities. Sadly when government and big business intersect, pragmatism and speedy reactions are rarely in evidence.

Follow @virusbtn
Follow @NakedSecurity

Image of Power failure cartoon courtesy of Shutterstock.


View the original article here

Thursday, August 8, 2013

Cyber vulnerabilities found in Navy's newest warship: official

By Andrea Shalal-Esa

WASHINGTON (Reuters) - The computer network on the U.S. Navy's newest class of coastal warships showed vulnerabilities in Navy cybersecurity tests, but the issues were not severe enough to prevent an eight-month deployment to Singapore, a Navy official said on Tuesday.

A Navy team of computer hacking experts found some deficiencies when assigned to try to penetrate the network of the USS Freedom, the lead vessel in the $37 billion Littoral Combat Ship program, said the official, who spoke on condition of anonymity.

The Freedom arrived in Singapore last week for an eight-month stay, which its builder, Lockheed Martin Corp., hopes will stimulate Asian demand for the fast, agile and stealthy ships.

"We do these types of inspections across the fleet to find individual vulnerabilities, as well as fleet-wide trends," said the official.

Cybersecurity is a major priority for the Navy, which relies heavily on communications and satellite networks for its weapons systems and situational awareness.

Defense Department spokeswoman Jennifer Elzea said the Pentagon's chief weapons test agency addressed "information assurance vulnerabilities" for the Littoral Combat Ship in an assessment provided to the Navy.

"The details of that assessment are classified," Elzea said.

Lockheed spokesman Keith Little said the company was working with the Navy to ensure that USS Freedom's networks were secure during the deployment.

The Navy plans to buy 52 of the new LCS warships in coming years, including some of Lockheed's steel monohull design and some of an aluminum-hulled LCS trimaran design built by Australia's Austal. The ships are designed for combat and other missions in shallower waters close to shore.

Freedom's first operational deployment was in the Caribbean Sea in 2010, where the ship participated in four drug transport busts and captured a total of five tons of cocaine.

(Reporting by Andrea Shalal-Esa; Additional reporting by David Lawder; Editing by Eric Beech and Stephen Coates)


View the original article here

Thursday, July 4, 2013

North Korea behind cyber attack: South Korea

Seoul, April 10 (IANS) The South Korean government Wednesday confirmed that North Korea was behind the March 20 cyber attack that paralyzed computer networks at banks and broadcasters.

"The series of cyber attacks last month resembled North Korea's past hacking patterns," the Ministry of Science, ICT & Future Planning said at a press briefing.

"Evidences (showed) that North Korea's reconnaissance general bureau did the act."

On March 20, computer networks at three banks and three broadcasters suffered the cyber attack, crippling about 48,700 PCs and servers, reported Xinhua.

On March 25, there was an attempt to hack PCs of the ordinary people, while computer files at the broadcaster YTN's 58 PCs were destroyed and data at anti-North Korean organizations' homepage were deleted the following day.

Based on 76 malicious codes used for the hacking and Internet access records collected, the March cyber attack was planned at least eight months ago by indirectly planting malware in advance, according to the probe results by the government-led investigation team.

The investigation team found that six PCs in North Korea directly or indirectly accessed the infected computers some 1,590 times, among which Internet Protocol (IP) address linked directly to North Korea was spotted 13 times.


View the original article here

Wednesday, June 6, 2012

Flame malware - more details of targeted cyber attack in Middle East

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Filed Under: Featured, Malware

Flame image courtesy of ShutterstockEarlier today, when I first reported on Flame malware that is said to have targeted Iranian computer systems, there was precious little detail.

It seems the reason for the scant information was that an embargo had been put on the media, who were waiting for the magic time of 2pm UK time to publish their stories.

Sure enough, this afternoon much more colour has been brought to the story and high profile news websites such as the BBC and Wired are telling the story of how Flame has been seen on computers in the Middle East, and Iran in particular.

Firstly, The Laboratory of Cryptography and System Security (CrySyS) at the Budapest University of Technology and Economics has published an indepth analysis on the malware, which it has named "Skywiper".

CrySyS's 63-page PDF report says that it began to analyse the malware earlier this month, and hypothesises that it was "developed by a government or nation state with signigficant budget and effort, and may be related to cyber warfare activities."

CrySys report

It is worth noticing that CrySyS received information about computers being infected with Skywiper in various countries, not just the Middle East. In fact, CrySyS noted that it had even received evidence of infections in it home country of Hungary.

One aspect of interest in CrySyS's report is how Skywiper attempts to evade detection by anti-virus products by storing its code in .OCX files (not usually checked by anti-virus products in their default configuration). However, if the malware detects the presence of McAfee's on-access scanner (McShield) it stores its code in .TMP files instead:

CrySys report

Other tricks that Skywiper/Flame might have up its sleeve may take some time to ascertain. It's code more than twenty times larger than Stuxnet, which means it could take substantial effort to analyse it all. Fortunately, complete code analysis is not necessary to add detection.

And now that the cat's out of the bag anyway - you have to ask yourself, who is likely to continue to use Skywiper/Flame now it has received this much attention both from the media and from the computer security industry?

At the same time as CrySyS's Skywiper report was released, anti-virus vendor Kaspersky published a report, claiming that the United Nations' International Telecommunication Union had approached the firm asking it to analyse malware believed to be wiping information from Middle Eastern computers.

The top 7 countries affected by Flame, according to Kaspersky

Kaspersky's Alexander Gostev wrote that Flame (as he called the malware that the Russian firm analysed) "might be the most sophisticated cyber weapon yet unleashed."

Although Kaspersky was initially hesitant of suggesting that Skywiper and Flame (called "Flamer" by the Iranian authorities) were the same thing, it's now clear that they are.

SophosLabs is in the process of receiving samples of the malware and will add detection as soon as possible.

We will update this article as more information becomes available.

Follow @gcluley

Flames image courtesy of Shutterstock.


View the original article here

Friday, May 25, 2012

Cyber romance scams cost US victims $50 million in 2011

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Man internet dating, courtesy of ShutterstockA recent report about internet crime finds that lonely, middle-aged or elderly people, mostly in the US, are suckers for a good romance scam.

We - and when I say "we", I mean "people who aren't me", because I lost nothing to online dating in 2011 but did gain a really nice red umbrella on a first date - thought that we were dating decent, nice people, and we accepted the flowers, the poetry, and the declarations of undying love..

..and it all wound up costing us a total of $50.4 million.

That's the total reported losses from a collection of 5,663 romance-specific complaints. On average, each victim reported a loss of $8,900.

Victims forked out, typically, for airline tickets or to supposedly help out their newfound love.

The numbers come from the Internet Crime Complaint Center (IC3) in the US, a partnership between the National White Collar Crime Center, the US Department of Justice's Bureau of Justice Assistance and the FBI.

Last year, the IC3 received romance scam-related complaints at a rate of 15 a day, at a daily loss of about $138,000, or more than $5,700 an hour.

How, you may well ask, did the IC3 come up with those numbers?

The IC3's 2011 Internet Crime Report is based on the 314,246 total complaints the center received last year.

Out of that number, 115,903 complaints reported financial loss for a reported total loss of almost $500 million.

The report says that the IC3 staff review any complaints that claim a loss of more than $100,000.

Which makes it sound like they're taking it on faith when a complainer says he lost less than $100,000.

That's a lot of faith! I'd take the IC3's numbers on faith, too, except I just noticed that the report says that FBI-related scams were the most reported
offense, followed by identity theft and advance fee fraud, but the numbers in its pie chart on page 10 show that work-from-home scams clocked in at 17,352, and FBI scams clocked in at 14,350, so my head's all scrambled and my faith is shaken.

Pie charts from FBI report

I put in a call to the IC3, so if I hear back, I'll update the story, because mixed-up numbers will jeopardize my brilliant plan, which is to combine the top scams into a hybrid super-scam.

Any criminal entrepreneur can see that they should be combining these two money-makers and running FBI romance scams. Or perhaps work-from-home romance scams. Or even work-for-the-FBI-from-home-for-a-really-hot-FBI-boss-who-secretly-loves-you scam.

They'd rake it in, since FBI agents have a tendency to look like super agent Jason Bourne, aka Matt Damon, all buff and square-jawed.

Just take a look at the video in this article. It shows FBI agents sneaking a server back after they maybe glued some tracking software into its innards.

After seeing the buffitude of the agents therein, you'll surely agree with the reader who commented that he/she would appreciate romancing, or something along those lines, from such an FBI agent:

"Anyone got the name/number of MIB there? He looks HOT - he can install a trojan in my back door any day."

IC3On a more serious note, regardless of the IC3's head-scratching numbers, it can't be denied that people are getting scammed.

Victims get ripped off because they're lonely, or perhaps they get taken in by loan-intimidation scammers armed with accurate information, such as the victim's social security number or date of birth.

One of the most frequent type of scam offers money for people to work at home, and most typically the operation is coming from a cyber criminal using victims as mules to move stolen funds. This is one of the most pernicious crimes, since the victims/mules may face criminal charges.

The report has a slew of good tips on avoiding getting victimized in its Appendix I on page 20.

As far as I can tell, the tips for what to watch out for in fake job offers are perfect for avoiding fake lovers and fake FBI agent lovers, particularly the first one:

Be wary of inflated claims of product effectiveness. Be cautious of exaggerated claims of possible earnings or profits. Beware when money is required up front for instructions or products. Be leery when the job posting claims “no experience necessary.” Do not give your Social Security number when first interacting with your prospective employer. Be wary when replying to unsolicited emails for work-at-home employment.

Be careful out there, and good luck finding love or companionship that's real.

Follow @LisaVaas

Woman and man internet dating cartoons, courtesy of Shutterstock


View the original article here

Wednesday, May 9, 2012

Opinion: America is under cyber attack, so what should we do?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

crisis imageYesterday, the US House of Representatives announced “cybersecurity week,” kicking it off with a Subcommittee Hearing entitled "America is Under Cyber Attack: Why Urgent Action is Needed".

As you might imagine, they didn't hold back, launching the week with a Hollywood-blockbuster style introduction, rallying citizens to fight off evilness.

(The only problem is that we have yet to identify our masked, caped, and brightly underpanted cybersecurity star who'll whoosh in and lead us to peace-and-harmony ville.)

If only for entertainment purposes, I would urge you to watch or read the opening statement [PDF].

Here are a few snippets:

America’s computers and Internet infrastructure are under attack and every American is at risk.

...this is not a science fiction scenario. There are no shells exploding or foreign militaries on our shores. But make no mistake: America is under attack by digital bombs.

...it is not a matter of if, but when a cyber Pearl Harbor will occur.

They even bring up the horrors of 9/11 to really drive their point home.

What really ticks me off about this kind of hyperbolic rhetoric is that it is ridiculously emotive, designed to spread fear and doubt to everyone in earshot, and via the power of the internet, dribble down to the rest of us.

Do we really want our leaders whipping themselves into a frenzy of blind panic before they decide on their next steps? A subcommittee hearing is surely not the place for popcorn-munching dramatics. Am I nuts to want logical concerns brought to the table in a calm, orderly fashion, so they can be studied, analysed, debated and prioritised?

So, why all this drama? Are they trying to soften us up for something?

According to the EFF, this approach might be used to convince us that in order to keep us safe, government needs to pick away at our dwindling privacy.

While we think an increased focus on catching criminals using existing tools is a fine tactic that could be used by law enforcement, we fear the temptation for law enforcement to increase their surveillance capabilities in order to successfully go on the offensive in the context of computer crimes. This could mean things like breaking into people's computers without warrants, or disrupting privacy-enhancing tools like Tor.

The EFF raise a really good counterpoint: rather than just go all Steven Seagal on online baddies, perhaps we should look really, really closely at our current infrastructure.

Vulnerabilities, by their very name, are weaknesses in our defences. Why not focus on resolving these first?

Yes, it is painful to go back over already-written code, but combining the skills of penetration testers, white hats, forensic analysts and coders, we could review and strengthen today's infrastructures. We could also all do our bit to educate general users on why it is important to practice safe computing and how to do it.

The thing is, while there are charlatans in every industry, the security market is rich with clever experts who know how to problem solve quickly and laterally. These are the people we should rally together to review, and where necessary rethink, our current defence mechanisms and strategies.

But, it is much easier to pass laws to force everyone to divulge who they are, where they are, what they are doing, when they are doing it, etc etc. And don't worry about this information ever getting into the wrong hands, as we have our existing defences in place to protect the government databases housing all your information.

Oh, wait a minute....

Follow @caroletheriault

Crisis image courtesy of Shutterstock


View the original article here

Wednesday, November 23, 2011

Foreign hackers targeted US water plant in apparent malicious cyber attack ... - Washington Post (blog)

Foreign hackers caused a pump at an Illinois water plant to fail last week, according to a preliminary state report. Experts said the cyber-attack, if confirmed, would be the first known to have damaged one of the systems that supply Americans with water, electricity and other essentials of modern life.

Companies and government agencies that rely on the Internet have for years been routine targets of hackers, but most incidents have resulted from attempts to steal information or interrupt the functioning of Web sites. The incident in Springfield, Ill., would mark a departure because it apparently caused physical destruction.

Federal officials confirmed that the FBI and the Department of Homeland Security were investigating damage to the water plant but cautioned against concluding that it was necessarily a cyber-attack before all the facts could be learned. “At this time there is no credible corroborated data that indicates a risk to critical infrastructure entities or a threat to public safety,” said DHS spokesman Peter Boogaard.

News of the incident became public after Joe Weiss, an industry security expert, obtained a report dated Nov. 10 and collected by an Illinois state intelligence center that monitors security threats. The original source of the information was unknown and impossible to immediately verify.

The report, which Weiss read to The Washington Post, describes how a series of minor glitches with a water pump gradually escalated to the point where the pump motor was being turned on and off frequently. It soon burned out, according to the report.

The report blamed the damage on the actions of somebody using a computer registered to an Internet address in Russia. “It is believed that hackers had acquired unauthorized access to the software company’s database” and used this information to penetrate the control system for the water pump.

Experts cautioned that it is difficult to trace the origin of a cyber-attack, and that false addresses often are used to confuse investigations. Yet they also agreed that the incident was a major new development in cyber-security.

“This is a big deal,” said Weiss. “It was tracked to Russia. It has been in the system for at least two to three months. It has caused damage. We don’t know how many other utilities are currently compromised.”

Dave Marcus, director of security research for McAfee Labs, said that the computers that control critical systems in the United States are vulnerable to attacks that come through the Internet, and few operators of these systems know how to detect or defeat these threats. “So many are ill-prepared for cyber-attacks,” Marcus said.

The Illinois report said that hackers broke into a software company’s database and retrieved user names and passwords of control systems that run water plant computer equipment. Using that data, they were able to hack into the plant in Illinois, Weiss said.

Senior U.S. officials have recently raised warnings about the risk of destructive cyber-attacks on critical infrastructure. One of the few documented cases of such an attack resulted from a virus, Stuxnet, that caused centrifuges in an Iranian uranium enrichment facility to spin out of control last year. Many computer security experts have speculated that Stuxnet was created by Israel — perhaps with U.S. help — as a way to check Iran’s nuclear program.

More cybersecurity coverage

- Proactive steps against cyberattacks

- Pentagon: Offensive cyber attacks fair game

- Cyberspying report names China, Russia

- In cyberspace, growing calls for clarity on what U.S. can do to deter against attacks


View the original article here

Wednesday, October 26, 2011

SSCC 76 - Michael Kaiser, NCSA and Rob Strayer chat about cyber security

function utmx_section(){}function utmx(){}(function(){var k='2740995052',d=document,l=d.location,c=d.cookie;function f(n){if(c){var i=c.indexOf(n+'=');if(i>-1){var j=c.indexOf(';',i);return escape(c.substring(i+n.length+1,j')})();SSCC 76 – Michael Kaiser, NCSA and Rob Strayer chat about cyber security | Naked Security /* */×The press love Sophos's free anti-virus for Mac - fancy giving it a spin?Antivirus and Security Software from SophosGlobal websites    Press    About us    Contact usProductsSolutionsSupportSecurityPartnersNaked SecuritySkip to contentSearch for:

Archive by date |author |category

Send us a tip | Subscribe by RSS

Follow us on TwitterJoin us on FacebookCheck out the SophosLabs YouTube channelConnect with us on LinkedInMalwareSpamSocial networksData lossLaw & OrderApplePodcastVideoMoreAbout iOS 5 introduces security challenges and flawsHacker's phone call to Boston Police saying he defaced their website.. because he was bored SSCC 76 - Michael Kaiser, NCSA and Rob Strayer chat about cyber security

Over 100,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Don't forget you can subscribe to the SophosLabs YouTube channel to find all our latest videos.

Hi there! If you're new here, you might want to subscribe to our RSS feed for updates.

Already using Google+? Follow Naked Security's Graham Cluley for the latest security news.

On LinkedIn? Join the Naked Security discussion group and connect with your peers in the security industry.

We're very sorry, something happened and we couldn't sign you up. We'll try to fix it so please come back later and try again.

Congratulations, you've successfully signed up for our daily news! Check your inbox soon, we've sent you an email.

Sorry, that email doesn't look right to us so we haven't added it to our list.

We're adding your address to our list...

utmx_section("Newsletter intro text")

Want to see more? Get Naked Security headlines by email every day!

utmx_section("Newsletter button text")by Chester Wisniewski on October 23, 2011|91096Leave a commenthttp%3A%2F%2Fnakedsecurity.sophos.com%2F2011%2F10%2F23%2Fsscc-76-michael-kaiser-ncsa-and-rob-strayer-chat-about-cyber-security%2FSSCC+76+-+Michael+Kaiser%2C+NCSA+and+Rob+Strayer+chat+about+cyber+security2011-10-23+03%3A31%3A04Chester+Wisniewskihttp%3A%2F%2Fnakedsecurity.sophos.com%2F%3Fp%3D91096

Filed Under: Featured, Law & order, Malware, Podcast, Privacy

Sophos Security Chet Chat logoLeading up to the State of Cyber Security event we will be speaking at October 27th in Washington DC I interview the other panellists on their thoughts around cyber security.

First I interviewed Michael Kaiser the founder and chief executive of the National Cyber Security Alliance. The NCSA focuses on providing educational outreach to home users, schools and small businesses about staying safe online.

We talked about the challenges facing the public when going online and the goals for National Cyber Security Awareness Month. Michael also gave us a glimpse into what he will be discussing at our State of Cyber Security event.

Rob Strayer, Director of the National Security Preparedness Group at the Bipartisan Policy Center, also found some time to chat with me by phone this week. Staryer's group focuses on encouraging public/private cooperation on matters of cyber security.

Rob discussed the goals of the National Security Preparedness Group and why they think there is so much work to be done for better information sharing between the public and private sectors. Rob also shared a teaser about his presentation at our event on October 27th.


(21 October 2011, duration 11:58 minutes, size 8.6 MBytes)

You can also download this podcast directly in MP3 format: Sophos Security Chet Chat 76, subscribe on Stitcher, iTunes or our RSS feed.

Follow @chetwisniewskiDigg

Tags: #NCSAM11, Bipartisan Policy Center, chet chat, Michael Kaiser, NCSA, NCSAM, Podcast, Rob Strayer

iOS 5 introduces security challenges and flawsHacker's phone call to Boston Police saying he defaced their website.. because he was bored About the authorChester Wisniewski is a Senior Security Advisor at Sophos Canada. He provides advice and insight into the latest threats for security and IT professionals with the goal of providing clear guidance on complex topics.You can follow Chester on Twitter as @chetwisniewski or send him an email at chesterw@sophos.com.View all posts by Chester WisniewskiRelated PostsIT administrators await mammoth Microsoft security patch bundleThe state of cyber security - Join Sophos and the NCSA in Washington DCSophos Security Chet Chat 41SSCC 57 - Infosec Europe 2011, Facebook privacy4th grade root beer memory foils Facebook chat scammer4th grade root beer memory foils Facebook chat scammerImage (1) twitter-hacked.jpg for post 15581Twitter website struck by 'Iranian Cyber Army' hackersPopularRecentRelatedanonymous-phone-thumbHacker's phone call to Boston Police saying he defaced their website.. because he was boredLaw student triggers 22 legal complaints and likely audit of FacebookHow to find out everything that Facebook *really* knows about youios5250iOS 5 introduces security challenges and flawsgaddafi-malware-thumbMalware attack poses as bloody photos of Gaddafi's deathosborne-170Letter from HM Treasury? Just another scamosborne-170Letter from HM Treasury? Just another scamanonymous-phone-thumbHacker's phone call to Boston Police saying he defaced their website.. because he was boredChetChatLogo250SSCC 76 - Michael Kaiser, NCSA and Rob Strayer chat about cyber securityios5250iOS 5 introduces security challenges and flawsIT administrators await mammoth Microsoft security patch bundleThe state of cyber security - Join Sophos and the NCSA in Washington DCIT administrators await mammoth Microsoft security patch bundleThe state of cyber security - Join Sophos and the NCSA in Washington DCSophos Security Chet Chat 41SSCC 57 - Infosec Europe 2011, Facebook privacy4th grade root beer memory foils Facebook chat scammer4th grade root beer memory foils Facebook chat scammerImage (1) twitter-hacked.jpg for post 15581Twitter website struck by 'Iranian Cyber Army' hackersVideo posts

More videos this way

Nimda, Lion hole, scam bust, .CZ.CC and RIP Steve - 60 Sec SecurityNimda, Lion hole, scam bust, dot CZ dot CC and RIP Steve - 60 Sec Security 60ss-20110913-250Apple fakery, DNS hack, DigiNotar, Linux, Wikileaks - 60 Sec Securityterrytoad-250Facebook page hijacking locks out original admins [VIDEO]Bomb hoax, busts, ATM skimming, Twitter security, Google fined - 60 Sec SecurityBomb hoax, busts, skimming, Twitter security, Google fined - 60 Sec Security facebook-aflame-squareMacbooks, Korea, Spamford busted, phones lost, Anonymous threat - 60 Sec SecurityTwitter FeedSophosLabs: RT @gcluley: Listen to hacker telling police he hacked their website because he was bored http://t.co/fp1B4jSu #occupyabout 2 hours agogcluley: RT @nakedsecurity: Letter from HM Treasury? Just another scam http://t.co/3vn3tjoLabout 4 hours agogcluley: Listen to hacker telling police he hacked their website because he was bored http://t.co/9eGHHL9Iabout 6 hours agogcluley: Sophos podcast: Michael Kaiser, NCSA and Rob Strayer chat about cyber security http://t.co/GgI2afz3about 8 hours agoChetWisniewski: Sophos Security Chet Chat 76 #podcast - interview Michael Kaiser NCSA and Rob Strayer from Bipartisan Policy Center http://t.co/RsSqcKXvabout 12 hours ago
Follow us on TwitterJoin us on FacebookCheck out the SophosLabs YouTube channelConnect with us on LinkedInEnglishDeutschEspañolFrançaisItalianohttp://www.sophos.co.jphttp://www.sophos.cnhttp://tw.sophos.comhttp://kr.sophos.com© 1997-2010 Sophos Ltd. All rights reservedLegalPrivacyJobsRSSjQuery(document).ready(function($){ Gravatar.profile_cb = function( h, d ) { WPGroHo.syncProfileData( h, d );}; Gravatar.my_hash = WPGroHo.my_hash; Gravatar.init( 'body', '#wpadminbar' ); });

View the original article here