Showing posts with label Information Security. Show all posts
Showing posts with label Information Security. Show all posts

Monday, December 29, 2008

US: Getting the Ear of the New President


(Americanbanker.com) If you follow the logic of FBI Director Louis Freeh, a cyber attack against America is inevitable and will feel like another September 11. He compares the current lack of coherent strategy and national will to prevent such an attack to the shoulder-shrugging response Americans had when the USS Cole was nearly sunk in the Yemeni port of Aden in 2000. "Neither the country, nor its leadership on both sides of the aisle, were motivated by this," Freeh lamented in a speech to attendees at the SC World Congress in New York in early December.

Freeh's words preceded Congressmen Jim Langevin (D-RI) and Michael T. McCaul (R-TX), who discussed their advice to president-elect Barack Obama on how to address the daily cyber threats and attacks against the nation's government, military and civilian networks. Langevin and McCaul co-chaired the Commission on Cybersecurity for the 44th Presidency, which spent more than 15 months formulating recommendations. The report has two main takeaways: the president should replace the current hodge-podge approach to cyber security with a new National Office for Cybersecurity, which would be part of the Executive Office of the President; and the government should issue strong, mandatory authentication identities for critical cyber infrastructures such as finance.

The first recommendation seems painfully obvious. Several technologists with strong industry credibility have held a variety of cyber "Czar" posts - Richard ClarkAmit YoranGreg Garcia, and the latest, Rod Beckstrom - to little avail. Creating a National Office of CyberSecurity charged with creating a comprehensive national security strategy might actually accomplish that goal.

As for authentication, the committee gave the FFIEC kudos for promoting stronger authentication for online financial services but wants to extend that effort even further. The report envisions a world where the government issues digital credentials that require in-person proofing - similar to a drivers license - which can then be accepted online by merchants and banks with greater certainty. The challenge is twofold: protecting individual privacy while at the same time preventing commercial interests and the government from requiring overly burdensome authentication, which could violate civil liberties.

Another challenge for cybersecurity experts is that many people are vying for the ear of President-elect Obama. Will the issue of cybersecurity prevail? There were four members of the Obama transition team on the committee, notes Jerry Dixon, a former FBI cybersecurity guru who is now director of analysis at cybersecurity consultancy Team Cymru. "It'd be bad form for them to ignore their own writing, wouldn't it?"

Friday, December 19, 2008

Obama is looking for a Cybersecurity Czar

On Forbes you find now an article about the new Cyber-Security Czar position at the Whitehouse. One of the candidates is Rod Beckstrom, a visionary who strongly believes in Information Sharing and Open Collaboration. Co-Author of the best-selling "the Starfhish and the Spider: the unstoppable power of leaderless organizations, from Al-Qaeda to the Internet", is now head of the National Cyber Security Centre at the Department of Homeland Security, US. 



Tuesday, August 19, 2008

CPNI published a security assessment of the IP

CPNI has just published a new document on the security of the Internet Protocol.

"Much of the effort of the security community on the Internet protocols did not result in official documents (RFCs) being issued by the IETF (Internet Engineering Task Force) leading to a situation in which 'known' security problems have not always been addressed by all vendors," the report states. "As a result, any system built in the future according to the official TCP/IP specifications might reincarnate security flaws that have already hit our communication systems in the past."
http://www.cpni.gov.uk/Products/technicalnotes/3677.aspx



Monday, July 28, 2008

WSJ: U.S. Fears Threat of Cyberspying at Olympics

WASHINGTON -- A debate is brewing in the U.S. government over whether to publicly warn businesspeople and other travelers heading to the Beijing Olympics about the dangers posed by Chinese computer hackers.

According to government officials and security consultants, U.S. intelligence agencies are worried about the potential threat to U.S. laptops and cellphones. But others, including the State and Commerce departments and some companies, are trying to quiet the issue for fear of offending the Chinese, these people say.
Barack Obama became the first major presidential candidate to propose new cybersecurity policies Wednesday when he unveiled his cybersecurity strategy, which includes combating corporate espionage, shielding the country's Internet infrastructure and establishing a national cybersecurity adviser.
U.S. intelligence and security officials are concerned by the frequency with which spies in China and other countries are targeting traveling U.S. corporate and government officials. The Department of Homeland Security issued a warning last month to certain government and private-sector officials stating that business and government travelers' electronic devices are often targeted by foreign governments. The warning wasn't available to the public. [...]

Thursday, July 24, 2008

How a Classic Man-in-the-Middle Attack Saved Colombian Hostages

This is a very intersting article, written by Bruce Schneier and appeared on his blog and Wired.com, that shows how a man-in-the-Middle attack has been used to save the colombian hostages. Many Critical Infrstructure services and processes are vulnerable to this kind of attack, in particular when traditional communication media are used (telephone lines).
WIRED: Last week's dramatic rescue of 15 hostages held by the guerrilla organization FARC was the result of months of intricate deception on the part of the Colombian government. At the center was a classic man-in-the-middle attack.
In a man-in-the-middle attack, the attacker inserts himself between two communicating parties. Both believe they're talking to each other, and the attacker can delete or modify the communications at will.
The Wall Street Journal reported how this gambit played out in Colombia: "The plan had a chance of working because, for months, in an operation one army officer likened to a 'broken telephone,' military intelligence had been able to convince Ms. Betancourt's captor, Gerardo Aguilar, a guerrilla known as 'Cesar,' that he was communicating with his top bosses in the guerrillas' seven-man secretariat. Army intelligence convinced top guerrilla leaders that they were talking to Cesar. In reality, both were talking to army intelligence."
This ploy worked because Cesar and his guerrilla bosses didn't know one another well. They didn't recognize one anothers' voices, and didn't have a friendship or shared history that could have tipped them off about the ruse. Man-in-the-middle is defeated by context, and the FARC guerrillas didn't have any. [...]

Thursday, July 17, 2008

The security of energy, water, telecommunications and other vital European infrastructures is set to be strengthened by a new international project no

The pan-European 'Design of an Interoperable European federated Simulation network for critical Infrastructures' (DIESIS) project will develop advanced computer modelling and simulations to find and test points of vulnerability in these infrastructures, and develop ways to address them.
Europe's critical infrastructures, such as transport systems, gas lines, electricity supplies and communications, are becoming increasingly interdependent.

This makes understanding the complex relationships between them important because a breakdown in one can spark severe disruptions across many others, potentially affecting millions of people.

These failures can also spread quickly across many different countries, as happened in November 2006 when 13 countries including France, Italy, Germany, Portugal and Morocco lost electricity supplies after a high-voltage power line in Germany was temporarily shut without proper preparations.
Similarly, in 2002 Cyclone Ilse caused 12 billion euros of damage after flooding disrupted electricity, water supplies and waste water systems across regions of Germany, Austria and the Czech Republic.
Unravelling the complex interactions and interdependencies of cross-European infrastructures demands highly developed simulation tools. While simulators currently exist for certain infrastructures, none are capable of simulating the interaction of multiple interdependent systems. This severely limits how effectively nations can prepare for and respond to threats to their infrastructures ranging from natural disasters and IT failures to human error and acts of terrorism.
DIESIS aims to tackle this by developing advanced computer models and simulators that can test the robustness of these interdependent infrastructures, identifying weak spots where a failure in one could begin a catastrophic domino effect.
Professor Erol Gelenbe of Imperial College London's Department of Electrical and Electronic Engineering, one of the leaders of DIESIS, explains:
"Systems have weak spots and when they go down the costs and impact on people's lives are huge. These are highly complicated systems in their own right, so understanding the many ways in which they interrelate requires extremely complex modelling. Our aim is to come up with a simulation facility for constant study that can find weaknesses in systems and address them."
The project will also tackle smaller failures, which may go largely unnoticed but are nevertheless costly. Professor Gelenbe adds:
"If the internet system in Westminster is down for an hour because it has been attacked by hackers it won't make the headlines but it's very expensive for government and business. Those kinds of attacks happen very frequently. This project will help to make our entire critical infrastructure much more secure."
DIESIS is funded by 1.5 million euros over two years by the European Union under the Seventh Framework Programme. It will carry out the initial work that will pave the way for the establishment of a European Infrastructures Simulation and Analysis Centre.
The project sees Imperial College London working with large European public sector research organisations, including the Fraunhofer-Institute for Intelligent Analysis and Information Systems, Germany, Consorzio Campano di Ricerca per l'Informatica e l'Automazione Industriale, Italy, Ente per le Nuove Tecnologie, l'Energia e l'Ambiente, Italy, and the Netherlands Organisation for Applied Scientific Research.
More information on DIESIS is available at http://www.diesis-eu.org/

Friday, June 27, 2008

EU: USB flash drives 'pose real security threat' ENISA

USB flash drives 'pose real security threat'USB flash drives are being used to breach enterprise network security and install malicious code on corporate IT systems, a technology body has claimed. According to the European Network and Information Security Agency (ENISA), organisations allowing the unfettered use of such devices could be losing between 65,000 euros (£51,000) and 1.6 million euros (£1.3 million) for every security violation that is made. The agency, which shares best practices for minimising the risk of uncontrolled use of personal storage devices, also warned that as many as 90 per cent of the USB drives purchased by businesses last year were not encrypted or stored in secure locations. Andrea Pirotti, executive director of the ENISA, said: "The cost of a USB flash drive may be insignificant but the value of the data it might contain can be priceless. ENISA strongly encourages companies with highly regulated or sensitive data to better manage the use of 'plug-and-play' devices."

Tuesday, June 24, 2008

National Information Exchange Model

One of my favourit topics is Information Sharing and you find many articles in my blog about it. In US, to address the Homeland Security Presidential Directive HSPD-5 on Information Sharing, a partnership between US DOK and DHS launched the National Information Echange Model (NIEM) Initiative.
Below you find the links to their website, together with the link to an introductory presentation. Enjoy

Presentation: http://www.niem.gov/ppt/Chicago_EB_082007_FINAL.pdf

Website: www.niem.gov

Sunday, June 15, 2008

Fighting cyber terrorism

IMPACT, or International Multilateral Partnership Against Cyber Terrorism, is the first global public-private initiative against cyber terrorism.
Malaysia’s Prime Minister Abdullah Badawi has approved a US$13 million grant to lay the foundation of IMPACT, a not-for-profit global organisation, to rally efforts from governments, the private sector, and academia worldwide, against the growing threat of cyber terrorism. IMPACT, or International Multilateral Partnership Against Cyber Terrorism, is the first global public-private initiative against cyber terrorism. It drives collaboration among governments, industry leaders and cyber security experts to enhance the global community’s capacity to prevent and respond to cyber threats.The start-up grant will be used to construct the IMPACT building in Cyberjaya, Malaysia, and operations are expected to start in December. The fund will also finance the infrastructure for the four centres of IMPACT: the Centre for Training & Skills Development; the Centre for Security Certification, Research & Development; the Centre for Global Response; and, the Centre for Policy, Regulatory Framework & International Co-operation. Currently chaired by the Malaysian PM, the leadership of the International Advisory Board of IMPACT will be handed over to other member countries after the initial three-year term. “From the standpoint of the Malaysian government, their contribution is a gift to the global community. Someone has to start. They feel they’re just giving the seed,” said Mohd Noor Amin, Chairman, Management Board, IMPACT.
Warning SystemIMPACT is currently building two systems for its member countries. One is an early warning system. which will aggregate ‘feeds’ from IMPACT’s security partners and member countries, which will be redistributed across the world to member countries.Another is a collaboration system that, according to Amin, is a secure electronic platform enabling experts from member countries to collaborate with one another based on their specialty and niche areas.

Thursday, June 12, 2008

The Psychology of Security

Bruce Schneier in a recent interview to CSO magazine declared that after years of attention to the technical aspects, he has come to the conclusion that security is primarly about people.
In January he published this nice article on the Psychology of Security.

The Psychology of Security

Introduction
Security is both a feeling and a reality. And they're not the same.
The reality of security is mathematical, based on the probability of different risks and the effectiveness of different countermeasures. We can calculate how secure your home is from burglary, based on such factors as the crime rate in the neighborhood you live in and your door-locking habits. We can calculate how likely it is for you to be murdered, either on the streets by a stranger or in your home by a family member. Or how likely you are to be the victim of identity theft. Given a large enough set of statistics on criminal acts, it's not even hard; insurance companies do it all the time.
We can also calculate how much more secure a burglar alarm will make your home, or how well a credit freeze will protect you from identity theft. Again, given enough data, it's easy.
But security is also a feeling [...]

Monday, June 9, 2008

BERR Information Security Breaches Survey 2008 - PwC UK

BERR Information Security Breaches Survey 2008 - PwC UK: "BERR Information Security
has published the Information Security Breaches Survey 2008, managed by PricewaterhouseCoopers on behalf of the UK Department of Business, Enterprise and Regulatory Reform (BERR). This survey of UK businesses, carried out every two years, is the UK's leading source of information on security incidents suffered by businesses, both large and small.
The 2008 survey results were launched at the Infosecurity Europe exhibition on 22nd April 2008. There are two reports available:
A two page Executive Summary, downloadable here (0.5MB)
A 32 page Technical Report, downloadable here (1.1MB)"