Showing posts with label network security. Show all posts
Showing posts with label network security. Show all posts

Thursday, August 8, 2013

Universities Warned to Protect Their Computer Networks from China



In a July 16, 2013 article, a New York Times article Universities Face a Rising Barrage of Cyberattacks, Stanford University computer networks were attacked by China sources according to the article.  In another article about the same incident, Stanford Probes Breach, As Attacks on Universities Soar.

The attacks have been increasing in sophistication as well as in frequency, often going undetected, which is prompting university officials to reconsider the open nature of their networks.

“A university environment is very different from a corporation or a government agency, because of the kind of openness and free flow of information you’re trying to promote,” David J. Shaw, the chief information security officer at Purdue University, told the Times. “The researchers want to collaborate with others, inside and outside the university, and to share their discoveries.”
Some research universities work with government agencies on classified projects, but even those that don’t, like Stanford, still work on projects that produce patents and other intellectual property used in commercial, medical and academic fields. And intellectual property has become the prime target of many cyberattacks, officials say.


A threat map showing trace lines of where some attacks to the USA originate.
 
University attacks are gaining momentum and are very insipid.  According to Bill Mellon of the University of Wisconsin:

“We get 90,000 to 100,000 attempts per day, from China alone, to penetrate our system,” said Mr. Mellon, the associate dean for research policy. “There are also a lot from Russia, and recently a lot from Vietnam, but it’s primarily China.”
China and Russian Federation are two most frequent countries where unsolicited attacks come from, as a consensus of many computer security researchers. In today's cyberthreat landscape, universities, small to large businesses  - of all types, as well as non-profits should be most concerned about blocking these Internet traffic sources as much as possible. Today a simple subscription to an annual firewall protection service may be all that is needed to avoid these attacks.  Most institutions do not need to allow Internet traffic from China nor the Russian Federation.

One source of this problem are network capable printers. Another article in GCN.com How Hackers can Turn the Internet of Things into a Weapon explains, printers can allow easy access to any hacker who has found his or her way past the security of a private computer network.  Such devices have insecure webpages to help maintain things like drum life, toner quantity, number of printed pages, etc. Until businesses who produce these devices improve the security of them, it is very important to immediately alter the security on these devices to prevent the harboring of infections on private computer networks.

To view the daily reporting of attacks over the Internet, stop by ShawdowServer.org dedicated webpage to view statistics of these attacks.  Or consider visiting the threat portal at ArborNetworks.com for their interpretation of current Internet attack trends.


Thursday, December 8, 2011

An excellent blog post "The Top 10 countries with the most malicious networks" over at CountryIPBlocks has re-analyzed this list of data with interesting statistics. This original list claims the US is the biggest offender of malicious networks. This list was sorted by order of the countries with the largest NUMBER OF SPAM EMAILS.
  1. United States
  2. China
  3. Russia
  4. United Kingdom
  5. Germany
  6. Japan
  7. Brazil
  8. Romania
  9. Ukraine
  10. Turkey

Unfortunately, these results are skewed by not explaining that there is a greater per capita incidence of Intnet connected individuals. The brilliant people at CountryIPBlocks.net discovered that the ratio of NUMBER OF INFECTED NETWORKS to THE AMOUNT OF SPAM is probably the more accurate consideration. That re-adjusted Top 10 list looks like this:


Here are the results based on percentage of infected networks:
  1. Brazil 89%
  2. Turkey 54%
  3. Romania 39%
  4. China 32%
  5. Russia 11%
  6. United Kingdom 11%
  7. Japan 10%
  8. Ukraine 9%
  9. Germany 6%
  10. United States 6%





Wednesday, February 4, 2009

Menlo Technical Blog II


As the computer security industry grows and more people have sophisticated computers in the most remote places on Earth, street scams and gimmicks common place to other cities and countries are brought inside an average computer user's home and inside a corporate network.

Sophisticated programs can jump onto a home or corporate laptop and report back to their makers on user names and passwords used by people to websites like banking and brokerage accounts. More than simply logging these user names and passwords, the programs can monitor and track what is displayed by bank websites. They use not-so-sophisticated means of triggering computer users to gain access to this information; something as simple as designing an email that makes a person THINK they have to log in to a common website - like Facebook or Chase Bank - yet the link is a fake but almost indistinguishable from the official website

Corporate (aka Enterprise) computer users need to re-adjust their thinking to believe potentially everyone is a suspicious character, not just those outside of their 'circle of friends'. 

Human interaction has many security features taken for granted that is used each and every day. Features such as:
-the exact tone of a person's voice, 
-the precise image of a person, 
-their movements and body language, 
-the language phrasing, 
-smell of another person. 

All of these are kinds of authentication reminders that are taken for granted when interacting with people day to day.

While socializing online we are blind to these physical world security features built into our daily interactions. We use something like a "friend authentication" but accommodate for the online world restrictions. We allow for a certain flexibility when we don't have physical visual queues, like slightly strange behavior in what is written by people we know. To complicate this matter, instead of a familiar and live one-on-one interaction, many times it is one-to-many missing many of the common queues we use to socialize with a person - like personal jokes, movements and gesticulations. Many times, an email is written to more than one person, a blog post written for many to read, a Facebook wall posting to an audience, or a tumblr link or twitter post.  The familiar tone which people speak to relatives and in-laws maybe alarmingly strange to a friend. Everyone has a slightly different level of humor and communication with each of their various friends, especially in social media.

When a program is designed by a hacker, it usually tries to 'play' in that socialization realm of unfamiliar behaviors. Presenting a plea or request pretending to be a person they are not, they use a kind of 'hook' to snag people emotionally into their scam. 

Each aspect of online life and technology is leveraged differently, by different hackers. Mostly hackers are using social engineering to gain access to an important piece of your identity that gives them access to all of your personal information and family money institutions.

Hackers socially engineer through such means as:
-fake email notifications of a purchase with a confirmation link
-a fake UPS or US Post Office email that installs a fake virus that claims to be an anti-virus program
-notifications of a Facebook account update
-a free fun video game for a child or gambling site for bored person that requires a small installation of a program with hidden components that captures your keyboard use
-a link in an email or webpage to update information, that injects a program into the computer to track keyboard movements
-a .pdf file that is attached to an email, from a friend or contact who had their email or address book accessed by an rogue program 

These are ONLY SOME examples of the mechanics of a scam; to make people secure in a relationship and then use this trusted relationship within a context that makes you vulnerable.  These scams mostly are trying to hook people by relating to issues based around love, pain, politics or money - and use this hook as a means to distract while hiding their real intent.

As a information technology security firm, our goal is to secure corporate networks, help enterprises design reliable backup plans, and make everyone more aware of the types of Internet and computer attacks that threaten enterprise intellectual property.

This blog - as well as our other Menlo Technical Word Press Blog - will be used by Menlo Technology Consulting to announce products, services and current trends in Information Technology Security.