The Idaho National Laporatory's (INL) National and Homeland Security Division is one of serveral organisations inthe USA involved in CNII protection research.
The National and Homeland Security Division conducts sustainable programs focused in Global Security, Homeland Security, National Defense, Energy Security, and Special Programs.
Sunday, February 17, 2008
Hackers Gone Wild ... Hacks on a massive scale
While previously hacks may be one off incidents posing threats to a small segment. Today the scenario is different.
We're looking at massive, well-organized plans to take over vast portions of the Net. Case in point: The SQL Injection exploit that infected more 70,000 sites .. more.
We're looking at massive, well-organized plans to take over vast portions of the Net. Case in point: The SQL Injection exploit that infected more 70,000 sites .. more.
US plans to 'fight the net' revealed
A newly declassified document gives a fascinating glimpse into the US military's plans for "information operations" - from psychological operations, to attacks on hostile computer networks.
Should nations care and worry about this as a threat to their CNII, we dont really know. But apart from the US, it is possible that some other nations or organised entities have similar aspirations, if not plans. .. more..
Should nations care and worry about this as a threat to their CNII, we dont really know. But apart from the US, it is possible that some other nations or organised entities have similar aspirations, if not plans. .. more..
Cut cable disrupts Internet in Middle East
Two underwater cables in the Mediterranean Sea were damaged in January 2008, dragging Internet connections throughout the Middle East and in parts of Asia to a crawl. This is a classic example of massive interruptions to CNII, though the scenario if one for which most would not have incorporated in the list of probabilities .. more..
Further questions are raised about the said vulnerability, possible but deemed improbable. more
Further questions are raised about the said vulnerability, possible but deemed improbable. more
Thursday, January 3, 2008
The 5 Coolest Hacks of 2007
Hackers are creative folk, for sure. But some researchers are more imaginative and crafty than others. We're talking the kind of guys who aren't content with finding the next bug in Windows or a Cisco router. Instead, they go after the everyday things we take for granted even more than our PCs -- our cars, our wireless connections, and (gulp) the electronic financial trading systems that record our stock purchases and other online transactions. >> More ..
CISCO's 2007 Annual Security Report
CISCO has released its 2007 Annual Security Report which provides an overview of the combined security intelligence of the entire CISCO organisation. The report encompasses threat information and trends collected between January and September 2007, and provides a snapshot of the state of security for that period. The report provides recommendations from CISCO security experts and predictions of how identified trends will continue to unfold in 2008.
Security trends and recommendations are organized into seven major risk categories:
- Vulnerability
- Physical
- Legal
- Trust
- Identity
- Human
- Geopolitical
The report also provides a high-level perspective on the issues currently shaping the security space, as well as insights into how security professionals and businesses can expect the industry to change over the next several years. The report can be downloaded here.
Security trends and recommendations are organized into seven major risk categories:
- Vulnerability
- Physical
- Legal
- Trust
- Identity
- Human
- Geopolitical
The report also provides a high-level perspective on the issues currently shaping the security space, as well as insights into how security professionals and businesses can expect the industry to change over the next several years. The report can be downloaded here.
Antivirus Protection Worse Than a Year Ago
The effectiveness of antivirus software has fallen off, and more and more pests can now slip past these barriers. This is the sobering conclusion the german computer magazine c't comes to in issue 1/08 with a test on 17 antivirus solutions. For the first time, c't also tested the behavioural blocking system they use. >> More ..
LOGIIC – Linking the Oil and Gas Industry to Improve Cyber Security
LOGIIC is a unique collaborative forum (initiated by the US Department of Homeland Security) where government and industry are focusing on cyber security issues for the oil and gas industry that are best addressed collaboratively. The needs of the infrastructure owners and operators are driving the formation of projects, supported by government and independent experts. The forms for future collaboration are currently being established, and new projects will be forthcoming.
One such project was the the LOGIIC 2005-2006 Correlation Project.
The LOGIIC Correlation Project was a 12-month technology integration and demonstration project jointly supported by industry partners and the U.S. Department of Homeland Security Science and Technology Directorate (DHS S&T). The project demonstrated an opportunity to reduce vulnerabilities of oil and gas process control environments by sensing, correlating and analyzing abnormal events to identify and prevent cyber security threats.
A detailed description of the LOGIIC Correlation Project can be downloaded from here.
This collaboration model between Government and industry can be similarly applied to other industry sectors.
One such project was the the LOGIIC 2005-2006 Correlation Project.
The LOGIIC Correlation Project was a 12-month technology integration and demonstration project jointly supported by industry partners and the U.S. Department of Homeland Security Science and Technology Directorate (DHS S&T). The project demonstrated an opportunity to reduce vulnerabilities of oil and gas process control environments by sensing, correlating and analyzing abnormal events to identify and prevent cyber security threats.
A detailed description of the LOGIIC Correlation Project can be downloaded from here.
This collaboration model between Government and industry can be similarly applied to other industry sectors.
Labels:
Collaboration,
Government,
Industry,
Oil and Gas,
SCADA
SCADA Security and CNII - Digital Bond
This Digital Bond site is a site that has articles and blogs on SCADA security with a focus on CNII issues. There are several blog categories that discusses a wide range of related topics. Have a look at the site to get some key information and knowlegde about SCADA security. >> More ..
Wednesday, January 2, 2008
SCADA and Control System Security - Views From An Expert
Joseph Weiss is one of the leading experts in control system security. He provides some interesting insights about control systems and including SCADA, DCS and PLC and the security issues surrounding these in an interview found here.
He explains among other things that "A control system has several unique attributes. Number one, a control system must be absolutely highly reliable. It can't shut down very often. So, unlike a business system where you can shut it down over the weekend, the system that controls the power plant must have almost 100 percent reliability or some form of backup to maintain the 100 percent reliability. It is extremely important." This characteristic brings in itself a very unique perspective about security implementation related to control systems.
In a later part of the interview he has this to say about control systems getting hit: "My very, very, very strong feeling is, if and when we get hit, we will never know why we were hit. All we will know is breakers are opening, valves are closing, certain things are happening. But we won't have a clue as to why."
The interview contains a lot of other interesting insights and examples of incidents and lessons learnt that would be useful for anybody interested in CNII and control systems in particular. >> More ..
He explains among other things that "A control system has several unique attributes. Number one, a control system must be absolutely highly reliable. It can't shut down very often. So, unlike a business system where you can shut it down over the weekend, the system that controls the power plant must have almost 100 percent reliability or some form of backup to maintain the 100 percent reliability. It is extremely important." This characteristic brings in itself a very unique perspective about security implementation related to control systems.
In a later part of the interview he has this to say about control systems getting hit: "My very, very, very strong feeling is, if and when we get hit, we will never know why we were hit. All we will know is breakers are opening, valves are closing, certain things are happening. But we won't have a clue as to why."
The interview contains a lot of other interesting insights and examples of incidents and lessons learnt that would be useful for anybody interested in CNII and control systems in particular. >> More ..
ICT Security Education and Awareness for Students
Learning to use the Internet safely should begin at a young age in school so that the generation of youth has the basic knowledge to practice and infuse or inculcate safe Internet use when they join the workforce. Some students have the ability to explore and find out the best practices themselves while yet the majority of others need to be taught or guided. The Hacker Highschool site is one of several websites that provides easy to follow materials on safe Internet use for school children.
The Hacker Highschool project is the development of license-free, security and privacy awareness teaching materials and back-end support for teachers.
Today's kids and teens are in a world with major communication and productivity channels open to them and they don't have the knowledge to defend themselves against the fraud, identity theft, privacy leaks and other attacks made against them just for using the Internet. This is the reason for Hacker Highschool.
In HHS, you will find lessons on utilizing Internet resources safely such as web privacy, chat protection, viruses and trojans (malware), and the over-all focus on how to recognize security problems on your computer. HHS is a great supplement to student course work or as part of after-school and club activities.The HHS program is developed by ISECOM, a non-profit, open-source research group focused on security awareness and professional security development and accreditation. >> More ..
The Hacker Highschool project is the development of license-free, security and privacy awareness teaching materials and back-end support for teachers.
Today's kids and teens are in a world with major communication and productivity channels open to them and they don't have the knowledge to defend themselves against the fraud, identity theft, privacy leaks and other attacks made against them just for using the Internet. This is the reason for Hacker Highschool.
In HHS, you will find lessons on utilizing Internet resources safely such as web privacy, chat protection, viruses and trojans (malware), and the over-all focus on how to recognize security problems on your computer. HHS is a great supplement to student course work or as part of after-school and club activities.The HHS program is developed by ISECOM, a non-profit, open-source research group focused on security awareness and professional security development and accreditation. >> More ..
Labels:
Kids,
Safe Internet,
School,
Teachers,
Teens
Friday, December 28, 2007
Insecurities in Healthcare Applications
Healthcare applications can be exploited with disastrous consequences if not adequately secured.
Healthcare apps keep sensitive medical records of patients. Though different types of healthcare applications are exposed to different sets of threats, there’s a pattern to threats they face.
This articel discusses some of the exposures that healthcare applications face. >> More ....
Healthcare apps keep sensitive medical records of patients. Though different types of healthcare applications are exposed to different sets of threats, there’s a pattern to threats they face.
This articel discusses some of the exposures that healthcare applications face. >> More ....
Top Ten Information Security Risks of 2008
This list which in fact covers Threats, Vulnerabilities, Impacts, Risks and Controls assembled by the CISSP Forum and the ISO 27K Implementers' Forum. The list of course includes threats and risks to Critical Information Infrastructure.
Those who are still confused with the definition and differences of Threat, Vulnerabilityu, Impact, Risk and Control, this article does list and discuss the brief definitions and the actual lists of the above will illustrate the definition further.
This is a must read for all involved in security. >> More...
Those who are still confused with the definition and differences of Threat, Vulnerabilityu, Impact, Risk and Control, this article does list and discuss the brief definitions and the actual lists of the above will illustrate the definition further.
This is a must read for all involved in security. >> More...
Labels:
Controls,
Impact,
Risk,
Threat,
Vulnerability
Monday, December 3, 2007
Catch me if you can star offers IT security advice
Frank Abagnale started off on the wrong side of the law by deceit and forgery to earn large amounts of money but was later caught. This was in the 60s when he was a teenager. His forgery talents did not go unnoticed and he was offered a job with the FBI in lieu of the rest of his jail sentence. His job is ... of course ... to pin down on forgery crimes.
His adventures were told in a book and a subsequent movie called "Catch me if you can".
This article is an interview with him where amongst other things he explained that:
1. It is way easier to commit forgery today than 40 years ago
2. We can have all the sophisticated security systems but the weakest link is still the human link.
3. Some laws passed recently are plain stupid.
4. Ethics must be reintroduced in education and must be a part of corporate culture.
5. We must be thinking out of the box when addressing security.
6. Simple solutions should be preferred than sophisticated ones.
While the above points appear obvious, it is certainly refreshing from a person who has been on both sides of the law. His thoughts and views are certainly key pointers for any entity managing critical infrastructures to gain a lesson or two from the perspective of security.
His adventures were told in a book and a subsequent movie called "Catch me if you can".
This article is an interview with him where amongst other things he explained that:
1. It is way easier to commit forgery today than 40 years ago
2. We can have all the sophisticated security systems but the weakest link is still the human link.
3. Some laws passed recently are plain stupid.
4. Ethics must be reintroduced in education and must be a part of corporate culture.
5. We must be thinking out of the box when addressing security.
6. Simple solutions should be preferred than sophisticated ones.
While the above points appear obvious, it is certainly refreshing from a person who has been on both sides of the law. His thoughts and views are certainly key pointers for any entity managing critical infrastructures to gain a lesson or two from the perspective of security.
Top 5 Worst IT Security Mishaps of 2007
Even though 2007 is not over, there are more than sufficient contenders for the top 5 position of the worst IT Security Mishaps of 2007. Though most of the mishaps relate to substantial data leakage, the examples are enough to raise alarm and concern about security breaches in the most trivial of cicumstances. >> More ..
World on Brink of Cyber Cold War
A "cyber cold war" waged over the world's computers threatens to become one of the biggest threats to security in the next decade, according to a report published on Thursday.
About 120 countries are developing ways to use the internet as a weapon to target financial markets, government computer systems and utilities, internet security company McAfee said in an annual report. >> More ..
In yet another article titled "US warned of 'aggressive' Chinese cyberspying, it was mentioned that Chinese espionage poses "the single greatest risk" to US technology, a congressional advisory panel said on Thursday. The panel also called for efforts to protect industrial secrets and computer networks. >> More ..
About 120 countries are developing ways to use the internet as a weapon to target financial markets, government computer systems and utilities, internet security company McAfee said in an annual report. >> More ..
In yet another article titled "US warned of 'aggressive' Chinese cyberspying, it was mentioned that Chinese espionage poses "the single greatest risk" to US technology, a congressional advisory panel said on Thursday. The panel also called for efforts to protect industrial secrets and computer networks. >> More ..
Labels:
Countries,
Cyber Attack,
Cyber War,
Espionage,
Weapons
Tuesday, November 20, 2007
Did NSA Put a Secret Backdoor in New Encryption Standard?
In a recent article, Bruce Schneier, a renowned expert on cryptology and security highlighted that a new random-number standard (for encryption) includes an algorithm that is slow, badly designed and just might contain a backdoor for the US National Security Agency.
The standard is found in NIST Special Publication 800-90.
The article may be quite technical but is enough to raise concerns that backdoors may exist in a puportedly secure software component.
This leads to the conclusion and emphasis that it is imperative for nations to have their own indigeneous technologies inkey security areas in order to minimise exposure to shortcomings or backdoors that leave the system vulnerable to attacks or intrusions. >> More ..
The standard is found in NIST Special Publication 800-90.
The article may be quite technical but is enough to raise concerns that backdoors may exist in a puportedly secure software component.
This leads to the conclusion and emphasis that it is imperative for nations to have their own indigeneous technologies inkey security areas in order to minimise exposure to shortcomings or backdoors that leave the system vulnerable to attacks or intrusions. >> More ..
Monday, November 19, 2007
2006 OS Vulnerability Summary
This report analyses and discuss about the OS Vulnerabilities. >> More..
Wednesday, November 14, 2007
Make No Assumptions. Security Begins With the Basics. YOU
There have been previous news about vendors releasing software with viruses, security vendor sites being compromised and similar incidents.
The mishaps continue ...
In a recent news article in Network World Asia titled "Seagate ships virus-laden hard drives", it was reported that:
"If you bought one of Seagate's Maxtor Basics consumer hard drives recently, check it for viruses. Especially if you're a gamer.
Seagate is warning that a "small number" of its Maxtor Basics Personal Storage 3200 hard drives recently shipped with the Virus.Win32.AutoRun.ah virus, malicious software that "searches for passwords for online games and sends them to a server located in China," according to a note posted on the Seagate Web site. Only drives purchased since August 2007 are affected, Seagate said." >> More ..
This time it is gaming software players who are the targets. Could it be anything else next time like bank accounts or access to corporate sites .... the possibility is so broad.
In yet another article in Network World Asia titled "Indian news site dispensing malware", it was mentioned that:
"The Web site of IndiaTimes, the online news site of the Times Group, one of India's large news and entertainment groups, exposed visitors to malware, according to an advisory Friday by ScanSafe Inc.
ScanSafe first detected and blocked malware on the site on October 25. ScanSafe is still investigating the reach of this attack, but given the popularity of the site and the amount of malware involved, the company is urging caution, it said in its advisory Friday. Only certain pages of the Indiatimes.com are infected, the advisory added." >> More ..
The above news basically pass the message that all users should not make any assumptions about any hardware or software they acquire or install and any website that they access as the malware can be embedded in just about anywhere and in the most unlikely of all places.
Hence defence against the consequences of such incidents requires users to be sufficiently aware, educated and acculturated about good computing practices including:
1. Having good anti-malware protection that is installed and running
2. Access to credible sites only and avoid strange or unusual sites
3. Ensure that any devices plugged in especially the usb devices are scanned for viruses before use.
4. Reminding peers about good computing practices.
A good defence for both personal and organisational or corporate use begins with YOU.
It may be that through your simple negligence, the whole corporate network that you are using and critical systems can be affected.
The mishaps continue ...
In a recent news article in Network World Asia titled "Seagate ships virus-laden hard drives", it was reported that:
"If you bought one of Seagate's Maxtor Basics consumer hard drives recently, check it for viruses. Especially if you're a gamer.
Seagate is warning that a "small number" of its Maxtor Basics Personal Storage 3200 hard drives recently shipped with the Virus.Win32.AutoRun.ah virus, malicious software that "searches for passwords for online games and sends them to a server located in China," according to a note posted on the Seagate Web site. Only drives purchased since August 2007 are affected, Seagate said." >> More ..
This time it is gaming software players who are the targets. Could it be anything else next time like bank accounts or access to corporate sites .... the possibility is so broad.
In yet another article in Network World Asia titled "Indian news site dispensing malware", it was mentioned that:
"The Web site of IndiaTimes, the online news site of the Times Group, one of India's large news and entertainment groups, exposed visitors to malware, according to an advisory Friday by ScanSafe Inc.
ScanSafe first detected and blocked malware on the site on October 25. ScanSafe is still investigating the reach of this attack, but given the popularity of the site and the amount of malware involved, the company is urging caution, it said in its advisory Friday. Only certain pages of the Indiatimes.com are infected, the advisory added." >> More ..
The above news basically pass the message that all users should not make any assumptions about any hardware or software they acquire or install and any website that they access as the malware can be embedded in just about anywhere and in the most unlikely of all places.
Hence defence against the consequences of such incidents requires users to be sufficiently aware, educated and acculturated about good computing practices including:
1. Having good anti-malware protection that is installed and running
2. Access to credible sites only and avoid strange or unusual sites
3. Ensure that any devices plugged in especially the usb devices are scanned for viruses before use.
4. Reminding peers about good computing practices.
A good defence for both personal and organisational or corporate use begins with YOU.
It may be that through your simple negligence, the whole corporate network that you are using and critical systems can be affected.
Labels:
Compromised,
Hardware,
Malware,
Security Breach
Monday, November 12, 2007
Pentagon: Our new robot army will be controlled by malware
This article emphasises the importance of developing indigeneous technologies rather than outsource the critical elements.
A US defence department advisory board has warned of the danger that American war robots scheduled for delivery within a decade might be riddled with malicious code. The kill machines will use software largely written overseas, and it is feared that sinister forces might meddle with it in production, thus gaining control of the future mechanoid military.
The most eye-catching of the equipment mentioned is the lineup of the US Army's Future Combat Systems (FCS) programme. FCS was originally supposed to include a wide range of deadly unmanned systems, including a small, possibly rocket-firing flying Dalek, a heavily armed autonomous helicopter gunship, and a robot tank packing guided missiles and cannon. There would also be intelligent sensor minefields, droid-mule transport systems and loads of other stuff; and all of it is supposed to be linked together by a data network. >> More..
A US defence department advisory board has warned of the danger that American war robots scheduled for delivery within a decade might be riddled with malicious code. The kill machines will use software largely written overseas, and it is feared that sinister forces might meddle with it in production, thus gaining control of the future mechanoid military.
The most eye-catching of the equipment mentioned is the lineup of the US Army's Future Combat Systems (FCS) programme. FCS was originally supposed to include a wide range of deadly unmanned systems, including a small, possibly rocket-firing flying Dalek, a heavily armed autonomous helicopter gunship, and a robot tank packing guided missiles and cannon. There would also be intelligent sensor minefields, droid-mule transport systems and loads of other stuff; and all of it is supposed to be linked together by a data network. >> More..
Labels:
Backdoor,
Malicious,
Malware,
Secure Programming
Subscribe to:
Posts (Atom)