What are the Key Skills for Your Organization?
Upasana Gupta, Contributing Editor
Nearly a year ago, IBM's client organization suffered a major malware attack. When Don Weber, then an incident response professional with IBM, arrived on-site with his team, they demonstrated timeline-based analysis that quickly provided them with system-based artifacts associated with the malware on the compromised systems.
Although the malware solutions were able to tell them which systems were currently infected, they had no way of telling which systems had been compromised, or whether the malware had been removed or instead rolled over to something that was not being detected.
Using the information available, Weber and his team took a step back from data analysis and developed a perl-based tool that detected specific registry keys that would work on live systems. Using this tool, the client's security team was able to distribute and reach all of their resources. This allowed them to systematically (over the course of several days) identify approximately 10 systems out of over 30,000 that needed to be added to the scope of the incident.
To read the entire article, click here - http://www.govinfosecurity.com/articles.php?art_id=3060&rf=2010-11-05-eg&
Showing posts with label information security. Show all posts
Showing posts with label information security. Show all posts
Friday, November 5, 2010
Friday, October 22, 2010
The Future of Mobile Payments
Solutions are Here, But Security Remains Top Concern
By Tracy Kitten, Managing Editor
Mobile technology is already having a big impact on financial services, from remote banking to mobile payments. The continued proliferation of smart phones is only going to accelerate that impact. Mobile is already revolutionizing the way consumers interact with their financial institutions, and banks have to stay ahead of the technology and the security concerns.
Randy Vanderhoof, executive director of the Smart Card Alliance, says mobile banking is a given. Payments are now the next frontier, and a number of technologies and services, such as remote deposit capture, are converging to make mobile payments readily accessible to consumers.
"By 2011, we can expect to see more NFC (near-field communications)-enabled devices being rolled out by the handset manufacturers," Vanderhoof says. Once that happens, the connection between the mobile device and contactless payments will be bridged.
To read the entire article, click here - http://www.bankinfosecurity.com/articles.php?art_id=3017&rf=2010-10-19-eb
Tuesday, October 12, 2010
FTC: No Major PHR Breaches So Far
Only Incidents Listed Are Lost or Stolen Credentials
October 11, 2010 - Howard Anderson, Managing Editor, HealthcareInfoSecurity.com
In the year since the breach notification rule for personal health records took effect, no major breaches affecting 500 or more individuals have been reported, according to the Federal Trade Commission.
A personal health record is an "electronic record of identifiable health information on an individual that can be drawn from multiple sources and that is managed, shared and controlled by or primarily for the individual," according to the FTC.
Last year, the FTC issued a PHR breach notification rule, as called for under the HITECH Act. Under the rule, which took effect Sept. 24, 2009, major breaches must be reported to the FTC within 10 business days. PHR vendors, and certain companies with which they do business, must report any size breach to the individuals affected within 60 days. But they only have to report the smaller incidents to the FTC annually, 60 days after the start of the calendar year.
To read the entire article, click here - http://www.govinfosecurity.com/articles.php?art_id=2996&rf=2010-10-12-eg
October 11, 2010 - Howard Anderson, Managing Editor, HealthcareInfoSecurity.com
In the year since the breach notification rule for personal health records took effect, no major breaches affecting 500 or more individuals have been reported, according to the Federal Trade Commission.
A personal health record is an "electronic record of identifiable health information on an individual that can be drawn from multiple sources and that is managed, shared and controlled by or primarily for the individual," according to the FTC.
Last year, the FTC issued a PHR breach notification rule, as called for under the HITECH Act. Under the rule, which took effect Sept. 24, 2009, major breaches must be reported to the FTC within 10 business days. PHR vendors, and certain companies with which they do business, must report any size breach to the individuals affected within 60 days. But they only have to report the smaller incidents to the FTC annually, 60 days after the start of the calendar year.
To read the entire article, click here - http://www.govinfosecurity.com/articles.php?art_id=2996&rf=2010-10-12-eg
Saturday, August 14, 2010
ATM Access: Getting In Is Too Easy
By Tracy Kitten
Security is an interesting topic. We're all concerned about it, but we often overlook the most fundamental things.
Yesterday, I tapped a few bankers for comments about ATM security. In particular, I was fishing for some reaction to last week's ATM hack at the Black Hat Technical Security Conference. Two Windows CE-based ATMs were breached during a staged attack by security expert Barnaby Jack.
With ease, Jack opened the ATM's enclosure with a universal key he ordered over the Internet.
The ATMs - a Triton RL2000 and a Tranax 1700 - are most often deployed by retailers, community banks and credit unions. As Lilia Rojo, the director of operations for the $476 million El Monte, Calif.-based SCE Federal Credit Union, points out, credit unions are often looking for less-expensive ATM alternatives, relative to those produced by NCR and Diebold. "But we still want to know that the machines are secure," she says.
The Triton and Tranax ATMs are lower-volume machines, so they make sense for locations that aren't getting hit with, say, 2,000 cash withdrawals a month. But are they less secure? "It's certainly unsettling," Rojo tells me. "Not having the technical expertise, you rely on the manufacturer to help you with something like this - to stay one step ahead of these problems."
The problems Rojo refers to include the ease with which Jack showed how any hacker could access an ATM's operating system and ultimately take it over. In one case, Jack bypassed the ATM's remote management system. In another, he walked up and physically accessed the ATM's PC and infected it with malware saved to a thumb drive.
The former mode of attack is definitely disturbing - Jack bypassed the Tranax RMS. Triton, whose ATM was attacked by a thumb-drive-carried culprit, responded to the hacking of its authentication methodology with a patch.
How many institutions have downloaded and installed the patch? How many even know about the patch? That's definitely a concern. But more concerning is that the latter breach again exposes a security gap that has come up several times in recent weeks. With ease, Jack opened the ATM's enclosure with a universal key he ordered over the Internet.
To read the entire article, click here - http://blogs.bankinfosecurity.com/posts.php?postID=651&rf=2010-08-13-eb
Security is an interesting topic. We're all concerned about it, but we often overlook the most fundamental things.
Yesterday, I tapped a few bankers for comments about ATM security. In particular, I was fishing for some reaction to last week's ATM hack at the Black Hat Technical Security Conference. Two Windows CE-based ATMs were breached during a staged attack by security expert Barnaby Jack.
With ease, Jack opened the ATM's enclosure with a universal key he ordered over the Internet.
The ATMs - a Triton RL2000 and a Tranax 1700 - are most often deployed by retailers, community banks and credit unions. As Lilia Rojo, the director of operations for the $476 million El Monte, Calif.-based SCE Federal Credit Union, points out, credit unions are often looking for less-expensive ATM alternatives, relative to those produced by NCR and Diebold. "But we still want to know that the machines are secure," she says.
The Triton and Tranax ATMs are lower-volume machines, so they make sense for locations that aren't getting hit with, say, 2,000 cash withdrawals a month. But are they less secure? "It's certainly unsettling," Rojo tells me. "Not having the technical expertise, you rely on the manufacturer to help you with something like this - to stay one step ahead of these problems."
The problems Rojo refers to include the ease with which Jack showed how any hacker could access an ATM's operating system and ultimately take it over. In one case, Jack bypassed the ATM's remote management system. In another, he walked up and physically accessed the ATM's PC and infected it with malware saved to a thumb drive.
The former mode of attack is definitely disturbing - Jack bypassed the Tranax RMS. Triton, whose ATM was attacked by a thumb-drive-carried culprit, responded to the hacking of its authentication methodology with a patch.
How many institutions have downloaded and installed the patch? How many even know about the patch? That's definitely a concern. But more concerning is that the latter breach again exposes a security gap that has come up several times in recent weeks. With ease, Jack opened the ATM's enclosure with a universal key he ordered over the Internet.
To read the entire article, click here - http://blogs.bankinfosecurity.com/posts.php?postID=651&rf=2010-08-13-eb
Thursday, July 22, 2010
IT Security Profession: Heal Thyself
By Eric Chabrow
Governance of information security professional certification is a hodgepodge of professional associations and for-profit companies that develop and issue certifications. But a consensus of members of the Commission on Cybersecurity for the 44th Presidency, in a white paper issued earlier this week, believe there's a better way to certify IT pros: the establishment of Board of Information Security Examiners, which would set the standards for all related activities for certification.
To read the entire article, please click here - http://blogs.govinfosecurity.com/posts.php?postID=630&rf=2010-07-22-eg
Governance of information security professional certification is a hodgepodge of professional associations and for-profit companies that develop and issue certifications. But a consensus of members of the Commission on Cybersecurity for the 44th Presidency, in a white paper issued earlier this week, believe there's a better way to certify IT pros: the establishment of Board of Information Security Examiners, which would set the standards for all related activities for certification.
To read the entire article, please click here - http://blogs.govinfosecurity.com/posts.php?postID=630&rf=2010-07-22-eg
Monday, May 3, 2010
Global IT Security Disconnect
Government, business perceive cyber safety differently.
By Eric Chabrow
Government officials from around the world see their IT systems as being more secure than their private-sector counterparts, and businesses believe their computer systems as providing more safeguards than their government counterpart.
It's just one of several disconnects revealed in a survey conducted from April 19 to 26 and released this weekend by the EastWest Institute, a think tank that is holding an international cybersecurity conference in Dallas this week. EastWest Institute solicited responses from its extended network of public and private sector experts from around the world.
To read the entire article, click here - http://blogs.govinfosecurity.com/posts.php?postID=541&rf=2010-05-03-eg
By Eric Chabrow
Government officials from around the world see their IT systems as being more secure than their private-sector counterparts, and businesses believe their computer systems as providing more safeguards than their government counterpart.
It's just one of several disconnects revealed in a survey conducted from April 19 to 26 and released this weekend by the EastWest Institute, a think tank that is holding an international cybersecurity conference in Dallas this week. EastWest Institute solicited responses from its extended network of public and private sector experts from around the world.
To read the entire article, click here - http://blogs.govinfosecurity.com/posts.php?postID=541&rf=2010-05-03-eg
Wednesday, April 28, 2010
How to Respond to Vishing Attacks
Bank, State Association Share Tips for Incident Response Plan
By Linda McGlasson, Managing Editor
In early February, five financial institutions in four states -- Michigan, Wisconsin, Minnesota and Mississippi -- reported being hit by telephone-based phishing, or "vishing" attacks.
Those incidents were part of a series of similar attacks that have targeted institutions and their customers since last fall.
Vishing is a form of phishing, where instead of people receiving an email trying to lure them into giving personal information, the criminal uses a phone call, either live or automated, to attack the bank or credit union customer and get critical information. In response to this spree of attacks, banking/security leaders from one of the impacted states have put together a vishing incident response plan for financial institutions.
To read the entire article, click here - http://www.cuinfosecurity.com/articles.php?art_id=2457&rf=2010-04-26-ec
By Linda McGlasson, Managing Editor
In early February, five financial institutions in four states -- Michigan, Wisconsin, Minnesota and Mississippi -- reported being hit by telephone-based phishing, or "vishing" attacks.
Those incidents were part of a series of similar attacks that have targeted institutions and their customers since last fall.
Vishing is a form of phishing, where instead of people receiving an email trying to lure them into giving personal information, the criminal uses a phone call, either live or automated, to attack the bank or credit union customer and get critical information. In response to this spree of attacks, banking/security leaders from one of the impacted states have put together a vishing incident response plan for financial institutions.
To read the entire article, click here - http://www.cuinfosecurity.com/articles.php?art_id=2457&rf=2010-04-26-ec
Monday, April 19, 2010
Fighting Fraud In The Re-Set Economy
By Tom Field
Just back from the FICO World event in Miami, where yesterday I gave a presentation on "The State of Banking Information Security Today."
Such a pleasure to discuss these issues with folks who have a vested interest in banking and security, and I was most pleased to see representation from some of the nation's largest banking institutions, including Bank of America and JPMorgan Chase.
To read the entire article, click here - http://blogs.bankinfosecurity.com/posts.php?postID=525&rf=041710eb
Just back from the FICO World event in Miami, where yesterday I gave a presentation on "The State of Banking Information Security Today."
Such a pleasure to discuss these issues with folks who have a vested interest in banking and security, and I was most pleased to see representation from some of the nation's largest banking institutions, including Bank of America and JPMorgan Chase.
To read the entire article, click here - http://blogs.bankinfosecurity.com/posts.php?postID=525&rf=041710eb
Labels:
identity theft,
information security,
small business
Tuesday, April 6, 2010
Fraud Expert Details What Must Be Done To Protect Business Accounts
By Linda McGlasson, Managing Editor
What can - and should - a banking institution do to help protect its business customers?
Mike Urban, senior director of Fraud Solutions at FICO, has studied this question and offers his observations on how institutions and customers can fight back against the risks of online fraud.
"Really, the problem is that ACH fraud can be as lucrative or even more than physically breaking into a retail establishment and stealing card data," Urban says. "It can really be lucrative for a one-time hit on a business." This puts institutions and their business customers in a "Catch-22" position, because small and medium businesses want easy access to their accounts, and institutions look at fraud detection on these accounts as an added expense. "But somehow institutions and businesses have to get closer to the middle and strike the right balance," Urban says.
To read entire article, click here - http://www.cuinfosecurity.com/articles.php?art_id=2375&rf=040510ec
What can - and should - a banking institution do to help protect its business customers?
Mike Urban, senior director of Fraud Solutions at FICO, has studied this question and offers his observations on how institutions and customers can fight back against the risks of online fraud.
"Really, the problem is that ACH fraud can be as lucrative or even more than physically breaking into a retail establishment and stealing card data," Urban says. "It can really be lucrative for a one-time hit on a business." This puts institutions and their business customers in a "Catch-22" position, because small and medium businesses want easy access to their accounts, and institutions look at fraud detection on these accounts as an added expense. "But somehow institutions and businesses have to get closer to the middle and strike the right balance," Urban says.
To read entire article, click here - http://www.cuinfosecurity.com/articles.php?art_id=2375&rf=040510ec
Saturday, April 3, 2010
The Faces Of Fraud 2010
By Tom Field
I overheard someone at the recent RSA Conference saying that there were three main themes to the event: Cloud computing, cloud computing, cloud computing.
Well, I'd say there was a competing theme, and it's emerging as the storyline of 2010: Fraud, fraud, fraud.
Payment cards, ACH, ATM - these are the forms of fraud that have made the biggest news so far in 2010. But there's another variation preying upon banking institutions, too, and it deserves its own headlines.
To read the entire article, click here - http://blogs.cuinfosecurity.com/posts.php?postID=510&rf=040310ec
I overheard someone at the recent RSA Conference saying that there were three main themes to the event: Cloud computing, cloud computing, cloud computing.
Well, I'd say there was a competing theme, and it's emerging as the storyline of 2010: Fraud, fraud, fraud.
Payment cards, ACH, ATM - these are the forms of fraud that have made the biggest news so far in 2010. But there's another variation preying upon banking institutions, too, and it deserves its own headlines.
To read the entire article, click here - http://blogs.cuinfosecurity.com/posts.php?postID=510&rf=040310ec
Labels:
crime,
identity theft,
information security,
small business
Wednesday, March 24, 2010
Does Bill Ban President From Shuttering The Net?
By Eric Chabrow
The Rockefeller-Snowe Cybersecurity Act of 2010 adopts a carrot and twig approach to winning businesses cooperation on information security. It's heavy on incentives - the carrot - and light on regulation - the twig. No thick stick here, more of friendly jostling to get businesses to comply with initiatives to secure the nation's critical IT infrastructure.
The legislation, S. 773, comes up for a vote Wednesday before the Senate Commerce, Science and Transportation Committee, and if approved, would become the first major piece of cybersecurity legislation to reach the Senate floor this Congress.
To read the entire article, click here - http://blogs.govinfosecurity.com/posts.php?postID=497&rf=032410eg
The Rockefeller-Snowe Cybersecurity Act of 2010 adopts a carrot and twig approach to winning businesses cooperation on information security. It's heavy on incentives - the carrot - and light on regulation - the twig. No thick stick here, more of friendly jostling to get businesses to comply with initiatives to secure the nation's critical IT infrastructure.
The legislation, S. 773, comes up for a vote Wednesday before the Senate Commerce, Science and Transportation Committee, and if approved, would become the first major piece of cybersecurity legislation to reach the Senate floor this Congress.
To read the entire article, click here - http://blogs.govinfosecurity.com/posts.php?postID=497&rf=032410eg
Thursday, March 18, 2010
Dept. of Homeland Security's Top Cyber Leader: Our Defenses Are Getting Better
Asked what worries him the most about safeguarding government IT systems, Philip Reitinger demurs. "It's not a question of what worries me most; it is a question of the opportunities we have got," Deputy Undersecretary Reitinger, the top cybersecurity official at the Department of Homeland Security, said in an interview with GovInfoSecurity.com.
"We are connecting more and more systems, creating an increasingly complicated environment," Reitinger said. "The attackers are getting better and better and we are depending more on those systems from day to day to make sure that our very way of life can continue, that the ways we work and play will continue and we will be able to be successful."
Reitinger maintains the government's cyber defenses are getting better. "We need to continue to improve because the hackers and the bad guys have continued to improve and there are a lot of areas for improvement, but we are making significant efforts to do so," he said.
To read the entire article, click this link - http://www.govinfosecurity.com/articles.php?art_id=2035&rf=031710eg
"We are connecting more and more systems, creating an increasingly complicated environment," Reitinger said. "The attackers are getting better and better and we are depending more on those systems from day to day to make sure that our very way of life can continue, that the ways we work and play will continue and we will be able to be successful."
Reitinger maintains the government's cyber defenses are getting better. "We need to continue to improve because the hackers and the bad guys have continued to improve and there are a lot of areas for improvement, but we are making significant efforts to do so," he said.
To read the entire article, click this link - http://www.govinfosecurity.com/articles.php?art_id=2035&rf=031710eg
Tuesday, March 16, 2010
Another Information Security Breach - Insider Alleged to Hack TSA Computer
A Transportation Security Administration data analyst, the week after being notified he was about to lose his job, hacked into a government computer used to screen terrorists in an attempt to damage it, according to a federal indictment handed up last week.
A federal grand jury in Denver indicted Douglas James Duchak, 46, who pleaded not guilty. If convicted, Duchak faces up to 10 years in prison and a fine of not more than $250,000 for each count.
According to the FBI, Duchak worked at the TSA's Colorado Springs, Colo., Operations Center from August 2004 through Oct. 23, 2009, updating TSA computers with information from the Terrorist Screen Database and U.S. Marshal's Service Warrant Information Network Database. TSA informed Duchak on Oct. 15 that he would lose his job on Oct. 30.
To read the entire story, click here - http://www.govinfosecurity.com/articles.php?art_id=2296
A federal grand jury in Denver indicted Douglas James Duchak, 46, who pleaded not guilty. If convicted, Duchak faces up to 10 years in prison and a fine of not more than $250,000 for each count.
According to the FBI, Duchak worked at the TSA's Colorado Springs, Colo., Operations Center from August 2004 through Oct. 23, 2009, updating TSA computers with information from the Terrorist Screen Database and U.S. Marshal's Service Warrant Information Network Database. TSA informed Duchak on Oct. 15 that he would lose his job on Oct. 30.
To read the entire story, click here - http://www.govinfosecurity.com/articles.php?art_id=2296
Subscribe to:
Posts (Atom)
Do Do You Keep Your Career Options Open?
OSBW Blog Archive
- January (1)
- October (3)
- September (1)
- March (2)
- December (1)
- November (1)
- October (4)
- August (1)
- March (2)
- February (1)
- January (3)
- December (13)
- November (11)
- July (2)
- March (2)
- February (1)
- January (2)
- December (7)
- November (9)
- October (17)
- September (11)
- August (5)
- July (15)
- May (3)
- April (7)
- March (23)
