Google Search

Showing posts with label network. Show all posts
Showing posts with label network. Show all posts

Wednesday, June 11, 2014

Finding the hidden zombie in your network: Statistical approach to unraveling computer botnets

How do you detect a "botnet," a network of computers infected with malware -so-called zombies -- that allow a third party to take control of those machines? The answer may lie in a statistical tool first published in 1966 and brought into the digital age researchers writing this month in the International Journal of Electronic Security and Digital Forensics.

Millions of computers across the globe are infected with malware, despite the best efforts of public awareness campaigns about phishing attacks and antivirus software. Much of the infection is directed towards allowing a third party to take control of a given machine or indeed a network of machines and exploiting them unbeknownst the legitimate users in malicious and criminal activity. Security and software companies do monitor internet activity and there have been many well-publicized successes in destroying such botnets. However, malware writers are always developing new tools and techniques that allow them to infect unprotected computers and rebuild botnets.

Botnets are widely used in organized crime to attempt breaches on security systems by mounting distributed denial of service (dDOS) attacks, among other techniques, on corporate, banking and government systems. Such attacks can open up "backdoors" into a private computer network that lets the botnet controller access proprietary and other sensitive information, passwords or even voting systems. Botnets have also been used for simply malicious purposes to force websites and other services offline, occasionally in an act of protest or rebellion.

Now, R. Anitha and colleagues at PSG College of Technology, Coimbatore, India, have turned to a statistical tool known as the hidden semi-Markov model (HsMM) to help them develop monitoring software that can detect the telltale signs of botnet activity on a computer and so disable the offending malware. In probability theory and statistics, a Markov process is one in which someone can predict the next state of a process based on its current state without knowing the full history of the process. An example in gambling would be that if you have chip now and the odds of winning or losing on the next bet are even then we can predict without knowing how many chips you had earlier that you will either have none or two after the next bet.

A hidden-Markov model would thus include variables of which the observer has no sight but can infer and so predict an outcome. Predicting whether it rained on a given day based on whether a fair-weather-only walker was out on a given day without you having a weather report for their area involves a hidden-Markov process. A hidden semi-Markov model then involves a process of this sort but where the time-elapsed into the current state affects the prediction. For example, one might predict the rainfall pattern based on how long it is since our fair-weather walk last ventured out.

The team has applied the statistical logic of the hidden semi-Markov model to forecast the characteristics of internet activity on a given computer suspected of being a "zombie computer" in a botnet based on management information base (MIB) variables. These variables are the components used to control the flow of data packets in and out of the computer via the internet protocol. Their approach can model the "normal" behavior and then highlight botnet activity as being a deviation from the normal without the specific variables that are altered by the malware being in plain sight.

The team points out that botnet and malware developers have focused recently on web-based, http, type activity, which is easier to disguise among the myriad packets of data moving to and fro across a network and in and out of a particular computer. Their tests on a small zombie computer network shows that the hidden semi-Markov model they have developed as a lightweight and real-time detection system can see through this disguise easily. If implemented widely such as system could lock down this kind of botnet very quickly and slow the assimilation of zombie computers by criminals and others with malicious intent.


View the original article here

Saturday, August 24, 2013

Network gaming company uses its “cheat-prevention” client to build a Bitcoin botnet

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

In one episode of the nerdtastic TV sitcom Big Bang Theory, the socially-challenged Caltech physicist antihero, Dr Sheldon Cooper, has his World of Warcraft account hacked.

A giant shopping-list of Sheldon's virtual property gets plundered: his wand of untainted power, all his gold, and even Glenn, his beloved battle ostrich.

As Sheldon laments, "Three thousand hours. Three thousand hours clicking on that mouse, collecting weapons and gold. It's almost as if it was a huge waste of time."

And that's the problem with games that you play across the internet: how do you trust the other people in the contest?

Even when there's no money involved, it spoils the fun if the other guys aren't on the level.

That's where on-line communities like ESEA, or E-Sports Entertainment, come into play.

ESEA describes itself on Facebook as "the leading game play based community. With a sweet pick up game mod, a custom anti-cheat client that works, and cool statistics to log all of your activity, ESEA is the place to play!"

To join ESEA's network, you need to install and use the company's custom client software.

The client is designed, amongst other things, to maintain a level playing field by detecting cheats, such as players who programmatically automate tasks - rapid, accurate shooting, for instance - that are supposed to be a battle of dexterity between human opponents.

Imagine the stirrings of discontent when players on ESEA's network started wondering about symptoms such as their GPUs (graphics processing units, the special graphics cards that speed up the display) running at high utilisation.

Overcooking your GPU can be a costly exercise, since it increases electricity consumption and may shorten the life of your hardware.

What was causing the hot and heavy running?

Surreptitious Bitcoin mining, it seems!

One customer took the simple precaution of looking in the ESEA client log file and found this:

Another user got in telephonic contact with a sysadmin at ESEA to discuss what was going on, and received some surprising admissions during the call.

Here's a partial transcript of the sysadmin's comments:

It shouldn't be any surprise, but the [anti-cheat] client is capable of doing a lot of things that people don't know about. [...] They think the client does screenshots and that's about it. Truth be told...it probably does more than about 50 different things, because there are more than 50 ways to cheat.

[...] Funnily enough, there was a debate, a conversation, regarding the subject of using the client to mine Bitcoins. That was a joke, but at the same time it was half serious.

The high-performance GPUs that many gamers own are handy for Bitcoining, because the Bitcoin system relies on computing massive numbers of SHA checksums, a task that just happens to be ideally suited to today's graphics hardware.

The ESEA staffer continues, rather unconvincingly:

It turned out I actually did write code to do it, but it wasn't supposed to be code that was everywhere. [...] I restarted the server and the [configuration] setting got reset and [the mining code] actually got turned on, which was only, like, it wasn't for very long.

We calculated how much we would actually make, if we really wanted to do it. We would make hundreds of thousands of dollars if we actually did it with everybody. But that would be pretty intense.

[Voice of caller] Not to mention kind of illegal.

And that's the problem with software that you run across the internet: how do you trust the other people in the protocol?

Even if there's no money involved, it spoils the fun if the other guys aren't on the level.

ESEA head honcho Torbull has now tried to make a clean breast of it, admitting that the company had toyed with the idea of using its customers as a giant Bitcoin botnet, but decided not to go ahead.

Nevertheless, someone inside the company didn't listen, and ran a Bitcoin farm on ESEA customers' computers for the next two weeks.

The outcome fell far short of the hundreds of thousands of dollars predicted above, but was nevertheless a handy sum to accumulate for free: just under $4000's worth of Bitcurrency.

It's a funny sort of infringement, because the Bitcoins weren't actually stolen, and the client software was voluntarily installed by each user, no doubt under terms and conditions that permit fairly arbitrary remote updates and reconfiguration.

Indeed, the Bitcoins didn't even exist until before the unauthorised mining started.

ESEA has decided to donate the proceeds to charity, to chip in the same amount again itself, and to create a prize pool for customers that will return $3,713.55 back into its customer community.

Peace with honour?

Probably - but it does raise the age old question: who will guard the guards?

Follow @duckblog


View the original article here

Tuesday, August 6, 2013

The World’s First International Ethical Hacking, Computer Network Defense and Forensics Competition Global ...

Global CyberLympics an online Ethical Hacking game announces its newly formed Advisory Board, including but not limited to: Curtis Levinson United States NATO Cyber Defense Advisor, Sali Osman Cyber Security Advisor for GE Capital, and Balaji Venketeshwar the Vice President of Information Security at BA Continuum.

Albuquerque, NM (PRWEB) April 22, 2013

Global CyberLympics, an international ethical hacking, cyber security online game is proud to announce its newly formed advisory board. The Advisory Board is made up of the following members:

Sharvind Appiah, Chief Information Officer of GEODIS Group


Dr. Abu Hasan Ismail, CEO and Founder of Prestariang Berhad


Curtis Levinson, United States NATO Cyber Defense Advisor


Sali Osman, Cyber Security Advisor for GE Capital


Todd Salmon, Director of Security Assessments at FishNet


Marc Atayi, President and CEO of Techworld International


Balaji Venketeshwar, Vice President of Information Security at BA Continuum (A wholly owned subsidiary of Bank of America in Asia pacific and Latin America)


Roberto Puyó Vallardes, Chief Information Security Officer at ONP (Ministry of Economy of the Government of Peru)

Jay Bavisi, President of the Global CyberLympics Organization Committee stated “The Advisory Board is as diverse as our players, and are representative of different areas around the globe. With their feedback, we can improve the games.” The Advisory Board will counsel the Global CyberLympics Organization committee on the following topics: development of the games, proficiency of the games, sponsorships, game continuity, and promotion of the games.

For more information contact Janelle McLean -Program Coordinator of Global CyberLympics at Janelle.mclean(at)eccouncil(dot)org.

About the 2012 Global CyberLympics Games


The 2012 Global CyberLympics grew by over 200%, and increased the number of Countries that participated from 27 to 52. Last year’s world finals competition was an action packed 6 hours with hacker teams changing positions several times as they jockeyed for top honors. These final games drew a consistent crowd as Hacker Halted conference goers gathered to see which flags (servers) teams were capturing. In the end team Hack.ERS from the Netherlands were able to defend their World Championship title, as they reclaimed 1st place for the second year in a row. The 2nd place team was the University of Maryland University College (UMUC) Cyber Padawans of the USA and the 3rd place spot went to team gula.sh of Hungry.

About the EC-Council Foundation


EC-Council Foundation is a charitable and educational organization dedicated to educating and training individuals in security skills; it is the founding company for Global CyberLympics an international computer defense, and ethical hacking competition. EC-Council Foundation’s application for recognition of its exemption from federal income tax under §501(c)(3) of the Internal Revenue Code is pending with the Internal Revenue Service.

EC-Council Foundation was established in 2012 by the founders of the International Council of E-Commerce Consultants (EC-Council). The International Council of E-Commerce Consultants (EC-Council) a member-based organization that certifies individuals in e-business and information security skills. It is the owner and creator of the world famous Certified Ethical Hacker (CEH), Computer Hacking Forensics Investigator (CHFI), EC-Council Certified Security Analyst (ECSA), License Penetration Tester (LPT), and numerous others that are offered in over 87 countries through more than 450 training partners globally. EC-Council has trained over 90,000 individuals and certified more than 40,000 security professionals.

For more information about Global CyberLympics and EC-Council Foundation, please visit http://www.cyberlympics.org

Janelle McLean
EC-Council Foundation
505-922-2885
Email Information


View the original article here

Saturday, June 22, 2013

Scribd, "world's largest online library," admits to network intrusion, password breach

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

San Francisco-based document sharing site Scribd has admitted to a network intrusion.

Scribd bills itself as The World's Largest Online Library, and with a suggested 50 million users or more, it's hardly surprising that the site has attracted the attention of cybercriminals.

Details are scant, but a notification published on the company's online Support Desk states:

Earlier this week, Scribd's Operations team discovered and blocked suspicious activity on Scribd's network that appears to have been a deliberate attempt to access the email addresses and passwords of registered Scribd users.

Because of the way Scribd securely stores passwords, we believe that the passwords of less than 1% of our users were potentially compromised by this attack.

We have now emailed every user whose password was potentially compromised with details of the situation and instructions for resetting their password.

Therefore, if you did not receive an email from us, you are most likely unaffected.

The comment that less than 1% of users were potentially compromised "because of the way Scribd stores passwords" could probably have been made more clearly.

At first blush, I was inclined to interpret this to mean that 99% of passwords were stored securely, presumably by salting and hashing, leaving only a small proportion open to the scrutiny of intruders.

? We've seen cases before where websites have upgraded their password handling systems to make them safer, but seem to have failed to migrate all users to the new system in a timely fashion, leaving some users in an insecure limbo.

The good news, if you read on, is that it looks as though none of Scribd's passwords are stored in cleartext, as the company goes on to say that:

Our investigation indicates that no content, payment and sales-related data, or other information were accessed or compromised. We believe the information accessed was limited to general user information, which includes usernames, emails, and encrypted passwords.

Scribd isn't claiming any certainty in what was taken (the verb believe implies acceptance without proof), but that's not unexpected.

Determining precisely what was stolen after an electronic break-in is tricky, and pedantic readers will be quick to point out that, technically, nothing was stolen because the original copies of the data remained behind.

Scribd also isn't clarifying how the passwords were encrypted, and the company probably doesn't actually mean encrypted, either.

Salting and hashing passwords is supposed to be a one-way process that allows the passwords to be verified, but not decrypted to reveal the original cleartext.

Assuming they were hashed and salted, then, stealing the password database doesn't directly reveal anyone's password.

But it does let the crooks mount an offline attack on the database, hashing a dictionary of passwords one-by-one and noticing when a guessed password is verified against the database of hashes.

And since Scribd isn't saying what password security algorithm it used, you have little choice but to assume it was a hashing process that doesn't slow down determined attackers much.

That's why the following behaviours are important:

When you choose a password, don't pick anything obvious. Attackers put the most likely passwords at the top of their dictionary lists, so the tougher your password, the later it will fall, if at all.Don't use the same password on multiple sites. Doing so means that your login details on the most important site are at risk from an attack on the least secure one.If you store password databases, use a strong salt-and-hash system (e.g. bcrypt, scrypt or PBKDF2) that makes it much harder and slower for attackers to go through their password dictionary, but not so slow that it's impracticable to verify individual passwords when your users login.

Scribd has put up an online "breach checker" which lets you check individual email addresses against the list of probably-pwned accounts:

It would have been a nice touch if the company had used HTTPS for this particular page, rather than sending your email address, and the notification of whether it was on the at-risk list, via unencrypted HTTP:

On the other hand, since anyone can check anyone's email address anyway, and since you probably received an email advising you to change your password already if your account was potentially pwned, it probably doesn't matter.

To learn more about managing, choosing and policing passwords in your organisation, why not listen to our popular Techknow podcast on this very topic?

(If you prefer to listen offline, you can download the podcast for later.)

Follow @duckblog


View the original article here

Tuesday, April 16, 2013

Facebook owns up - admits network breached, blames "Java in the browser"

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

There's a scene in the movie The Social Network where Mark Zuckerberg is arguing with Eduardo, his CFO.

Eduardo's just frozen Facebook's bank account.

The plan is to get Zuckerberg's attention and to try to get Zuck back on what Eduardo thinks is the straight and narrow.

But Zuckerberg is irate.

He thinks it might end up with an unpaid bill and thus a network outage, and that won't do!

Zuck rants:

Let me tell you the difference between Facebook and everybody else: WE DON'T CRASH EVER!

It's only a movie, of course.

In real life it's not true that Facebook never goes down, but when you consider its size and the online activity it supports, Facebook's uptime and availability is astonishing. Stellar. Intergalactic, even.

The movie version of Zuckerberg goes on to explain:

If the servers are down for even a day, our entire reputation is irreversibly destroyed. Users are fickle... Even a few people leaving would reverberate through the entire user base.

But what about getting owned by hackers?

What effect do you think that might have?

If you're the world's biggest social network, and if collecting, storing and using other people's personal information is your bread and butter?

Hold your horses, because we're about to find out.

Facebook just published an article entitled Protecting People On Facebook, and it doesn't cover what you might at first expect when you see the title.

Sure, it starts upbeat enough:

Facebook, like every significant internet service, is frequently targeted by those who want to disrupt or access our data and infrastructure. As such, we invest heavily in preventing, detecting, and responding to threats that target our infrastructure, and we never stop working to protect the people who use our service.

But that's followed by a hint of what's coming next:

The vast majority of the time, we are successful in preventing harm before it happens, and our security team works to quickly and effectively investigate and stop abuse.

And then the bombshell. OK, not really a bombshell. Let's be fair and say it's actually a pretty candid admission for which the company deserves at least a nod of respect:

Last month, Facebook Security discovered that our systems had been targeted in a sophisticated attack. This attack occurred when a handful of employees visited a mobile developer website that was compromised. The compromised website hosted an exploit which then allowed malware to be installed on these employee laptops.

Later on in the article, Facebook claims that it has "found no evidence that Facebook user data was compromised," and and for what it's worth, I'm willing to accept that claim.

? Update. In an interview with Ars Technica, Facebook CSO Joe Sullivan has admitted that the crooks made off with information from the laptops themselves. ("What you typically find on an engineer's laptop, including corporate data, e-mail, and some software code.") But despite being able to get "some limited visibility" into Facebook's production systems, Sullivan confirmed that a forensic review found no evidence that the crooks got away with any data off those systems. Close, in a word, but no cigar. (Added 2013-02-16T22:11Z)

The crooks had a Java zero-day at their disposal, and this exploit let them infiltrate Facebook's network and inject malware.

But the company says it was fully patched and anti-virused, and it sounds as though the malware that followed the exploit was quickly spotted and cleaned up, with no lasting harm done.

Just one suggestion to Facebook developers: why not read Naked Security?

We've given you loads of good reasons to turn off Java in your browser, starting from the middle of last year.

That alone could have side-stepped this problem.

Even just using a browser with click-to-play (so that Java and Flash applets, amongst others, can't launch quietly in the background from compromised websites) would surely have been enough.

I'm guessing now, but I'd be very surprised if the mobile developer website alluded to above actually required Java, so there would have been no reason to have Java turned on for that site.

Similarly, the mobile developer website could have considered using outbound web or packet filtering to block the egress of Java applets if, indeed, its site was never supposed to serve them up in the first place.

? IPS technology is usually thought of as a way to keep bad guys out, not least because it stands for intrusion prevention system. But most decent IPSes work bidirectionally, and can act as effective EPSes, or exfiltration preventers, too. You filter email for spam both ways (don't you?), because you can, and because it makes sense. The same applies with network traffic in general. If the bad guys have already got in, you may as well stop them getting back out as well!

Having said all that, it remains for me to ask. You have turned off Java in your browser, haven't you?

If not, here you are: How to turn off Java in your browser.

And fear not that you will break JavaScript: Java is not JavaScript.

Follow @duckblog


View the original article here

Sunday, July 8, 2012

SWAT team raids wrong home in open WiFi network cock-up [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

SWAT team. Image from ShutterstockIs your home WiFi network left open for anyone to use? Maybe this staggering story from America will make you think twice as to whether that's a good idea.

After spotting threats posted online, a heavily-armed police SWAT team broke down the door of a house in Evansville, Indiana, smashed windows and tossed a flashbang stun grenade into the living room where an eighteen-year-old girl and her grandmother were watching the Food Network.

Can you imagine how terrifying it must have felt to have been in that room when the grenade was thrown in, and the house stormed by police with their guns drawn?

Oh, and just a small detail - the police had the wrong house. The home had an open WiFi connection, which meant that it could be used from an outside location.

The dramatic events were helpfully captured on video, as the police had invited the local news station to record the raid (presumably their intention was to show themselves in a good light, rather than making a massive goof).

I'm not American, and don't live in America, so maybe you think I'm not entitled to ask this question, but I'm going to ask it anyway: What on earth is going on? Has the world gone entirely barking mad?

Okay, that out of the way - let's get on with the story...

The somewhat rattled Stephanie Milan and her family were released without charge once the mix-up became obvious, and police looked further afield for the culprit who had posted messages like the following online:

"Cops beware! I'm proud of my country but I hate police of any kind. I have explosives :) made in America. Evansville will feel my pain."

With a second suspect identified at a different house on the same street, police took a more softly-softly approach. This time not using a SWAT team or grenades, but instead using the tried-and-trusted traditional method of knocking on the door.

You would like to imagine that the authorities understand that many people still have poorly secured WiFi networks in their home, which can easily be exploited by people causing mischief, sending pornographic spam or even terrorist-related emails.

The Milans' door and window are now being repaired at the city's expense. And presumably the family are taking steps to secure their WiFi connection.

Follow @gcluley

Hat-tip: Ars Technica

SWAT team image courtesy of Shutterstock.


View the original article here