Several large US banks were attacked by hackers who appear to have used malware and a zero-day vulnerability to infiltrate networks and obtain corporate and customer data. At least five banks—only JP Morgan Chase was identified—were involved in the attacks, in which cybercriminals stole “gigabytes of customer data,” according to the anonymous sources cited by news outlets. However, it is unclear whether they took credit card or other account information. The fact that there have been no reports of money moved from accounts indicates the attack was politically motivated, according to a US government source. The US FBI, Secret Service, and National Security Agency are investigating the breaches. Initial investigations indicate the attacks were routed through computers in Latin America from servers that Russian hackers are known to use. Security vendor Trend Micro reported an uptick in attacks on US and European banks since 24 July 2014 from computers whose IP addresses appear to be in former Soviet bloc countries. JP Morgan Chase spokesperson Brian Marchiony declined comment on the recent incidents, saying only, “Companies of our size unfortunately experience cyberattacks nearly every day. We have multiple layers of defense to counteract threats and constantly monitor fraud levels.” In April, JPMorgan Chase CEO Jamie Dimon said the company was increasing its annual expenditures on security by 25 percent—to $250 million—compared to 2013. (CNN Money)(re/Code)(Bloomberg)
Google Search
Thursday, September 18, 2014
Monday, June 23, 2014
UK Government Amending Law, Wants Life Sentence for Malicious Hackers
The UK government wants to amend its current laws to let judges give a life sentence to computer hackers whose misdeeds result in loss of life or threaten national security. The 1990 Computer Misuse Act now gives hackers a maximum sentence of ten years. In the newly introduced Serious Crime Bill, cyberattacks resulting in loss of life, serious illness or injury, or serious damage to national security carry a life sentence while those resulting in serious economic or environmental damage carry a 14-year sentence. “Malicious hackers who risk triggering deadly civil unrest by cutting off food distribution, telephone networks, or energy supplies by sabotaging computer networks could be sentenced to life in prison,” according to the Telegraph. (SlashDot)(iTnews.com.au)(Telegraph)
Thursday, March 6, 2014
Hackers Breach Casino Sites
Hackers breached and defaced all the websites of Las Vegas Sands Corp., including the home pages for some of the world’s largest casinos. After the attack, the company down the sites, which includes those for the company, the Venetian and Palazzo casinos in Las Vegas, and the Sands casinos in Bethlehem, Pennsylvania, Singapore, and Macau. The attackers also stole and released some Sands employees’ personal information, including Social Security numbers, email addresses, and job titles. Company officials are still assessing the damages. Experts guess the attacks may have been politically motivated, as the hackers placed a photo of Sands CEO Sheldon Adelson posing with Israel Prime Minister Benjamin Netanyahu on the affected websites with a message condemning the use of weapons of mass destruction on the sites. Adelson, whose personal wealth is estimated to be at least $37 billion, is a vocal supporter of Israel and has met Netanyahu several times. He has also sought to have Internet gambling banned in the US. The Nevada State Gaming Control Board is investigating the breach. (Associated Press)(The Morning Call)
Tuesday, December 31, 2013
Report: Chinese Hackers Spy on Foreign Ministries
Chinese hackers reportedly eavesdropped on the computers of five European foreign ministries prior to the September 2013 G20 Summit of finance ministers and central bank governors from 20 major global economic powers, according to research by computer security firm FireEye. The hackers reportedly employed a phishing campaign that used malware-tainted e-mails, to load malicious code on victims’ PCs. FireEye researchers say they monitored the hackers’ main server used for about a week in late August 2013 but lost contact when operations moved to another server. FireEye did not identify the affected nations but said all were European Union members. The company reported the attacks to the US Federal Bureau of Investigation, which has declined comment. FireEye used technical evidence, including the language used on the control server, to determine the hackers are based in China. According to FireEye, the Chinese attackers are allied with the Ke3chang hacking group, which has been active since 2010 and typically targets aerospace, energy, and manufacturing firms. Whether the group is government-supported is unclear. The Chinese government has reportedly continued to deny any claims it has hacked foreign governments. (Reuters)(CNET)(BBC)
Friday, July 26, 2013
Opera Says Network Attack Lets Hackers Certify Malware
Browser maker Opera Software says an attack on its internal network took advantage of its update service and led to the theft of at least one old and expired code-signing certificate that hackers used to sign malware, making it look legitimate to victims and thus safe to use. This has allowed them to distribute malicious software that incorrectly appears to have been published by Opera Software or appears to be the Opera browser, Opera stated. The company released no other details. Because of the scheme, any Windows user who downloaded the malware thinking it was the Opera browser and tried to install the browser on 19 June 2013 may have installed the malicious software instead. This is an example of how hackers are increasingly focusing attacks on software firms’ internal networks -- which allows them to have the ability sign files and to escalate their own privileges in order to move more freely within the network -- rather than individual users, according to security experts. (SlashDot)(Security Week)(The Opera Security Group)
Wednesday, July 24, 2013
Tool Calculates Potential Value of E-Mail to Hackers
A new research tool scans a user’s Gmail account to calculate the potential benefit hackers could realize by exploiting the account and then stealing and selling valuable personal information. The Cloudsweeper tool, created by University of Illinois at Chicago researchers, uses the Open Authentication protocol that allows the tool to connect to a Gmail account and search through messages. It then provides a list of the number of retail accounts connected to that address, which include sites such as Amazon or Groupon, that attackers could seize should they gain access. The tool then consults its database and calculates the account’s value based on their current black-market resale price to hackers who want to use the data to steal money or for other illegal purposes. (SlashDot)(Krebs on Security)(Cloudsweeper)
Wednesday, October 24, 2012
App protects Facebook users from hackers
A recent four-month experiment conducted by several UC Riverside engineering professors and graduate students found that the application they created to detect spam and malware posts on Facebook users' walls was highly accurate, fast and efficient.
The researchers also introduced the new term "socware" -- pronounced "sock-where" -- to describe a combination of "social malware," encompassing all criminal and parasitic behavior on online social networks.
Their free application, MyPageKeeper, successfully flagged 97 percent of socware during the experiment. In addition, it was only incorrect -- flagging posts of socware that did not fit into those categories -- 0.005 percent of the time.
The researchers also found that it took an average of .0046 seconds to classify a post, which is far quicker than the 1.9 seconds it takes using the traditional approach of web site crawling. MyPageKeeper's more efficient classification also translates to lower costs, cutting expenses by up to 40 times.
"This is really the perfect recipe for socware detection to be viable at scale: high accuracy, fast, and cheap," said Harsha V. Madhyastha, an assistant professor of computer science and engineering at UC Riverside's Bourns College of Engineering.
Madhyastha conducted the research with Michalis Faloutsos, a professor of computer science and engineering, and Md Sazzadur Rahman and Ting-Kai Huang, both Ph.D. students. Rahman presented the paper outlining the findings at the recent USENIX Security Symposium 2012.
During the four-month experiment, which was conducted from June to October 2011, the researchers analyzed more than 40 million posts from 12,000 people who installed MyPageKeeper. They found that 49 percent of users were exposed to at least one socware post during the four months.
"This is really an arms race with hackers," said Faloutsos, who has studied web security for more than 15 years. "In many ways, Facebook has replaced e-mail and web sites. Hackers are following that same path and we need new applications like MyPageKeeper to stop them."
The application, which is already attracting commercial interest, works by continuously scanning the walls and news feeds of subscribed users, identifying socware posts and alerting the users. In the future, the researchers are considering allowing MyPageKeeper to remove malicious posts automatically.
The key novelty of the application is that it factors in the "social context" of the post. Social context includes the words in the post and the number of "likes" and comments it received.
For example, the researchers determined that the presence of words -- such as 'FREE,' 'Hurry,' 'Deal' and 'Shocked' -- provide a strong indication of the post being spam. They found that the use of six of the top 100 keywords is sufficient to detect socware.
The researchers point out that users are unlikely to 'like' or comment on socware posts because they add little value. Hence, fewer likes or comments are also an indicator of socware.
Furthermore, MyPageKeeper checks URLs against domain lists that have been identified as being responsible for spam, phishing or malware. Any URL that matches is classified as socware.
During the four-month experiment, the researchers also found:
A consistently large number of socware notifications are sent every day, with noticeable spikes on a few days. For example, 4,056 notifications were sent on July 11, 2011, which corresponded to a scam that went viral conning users into completing surveys with the pretext of fake free products.Only 54 percent of socware links have been shortened by URL shorteners such as bit.ly and tinyurl.com. The researchers thought this number would be higher because URL shorteners allow the web site address to be hidden. They also found that many scams use somewhat obviously "fake" domain names, such as http://iphonefree5. com and http://nfljerseyfree. com, but users seem to fall for it and click the link.Certain words are much more likely to be found in Facebook socware than in e-mail spam. For example, "omg" is 332 times more likely to appear in Facebook socware. Meanwhile, "bank" is 56 times more likely to appear in e-mail spam.Twenty percent of socware links are hosted inside of Facebook.This activity is so high that the researchers expect that Facebook will have to do more to protect its users against socware.
"Malware on Facebook seems to be hosted and enabled by Facebook itself," Faloutsos said. "It's a classic parasitic kind of behavior. It is fascinating and sad at the same time."
App: https://apps.facebook.com/mypagekeeper/
Share this story on Facebook, Twitter, and Google:Other social bookmarking and sharing tools:
Story Source:
The above story is reprinted from materials provided by University of California - Riverside. The original article was written by Sean Nealon.
Note: Materials may be edited for content and length. For further information, please contact the source cited above.
Note: If no author is given, the source is cited instead.
Disclaimer: Views expressed in this article do not necessarily reflect those of ScienceDaily or its staff.
Thursday, September 27, 2012
Self-adapting computer network that defends itself against hackers?
Scott DeLoach, professor of computing and information sciences, and Xinming "Simon" Ou, associate professor of computing and information sciences, are researching the feasibility of building a computer network that could protect itself against online attackers by automatically changing its setup and configuration.
DeLoach and Ou were recently awarded a five-year grant of more than $1 million from the Air Force Office of Scientific Research to fund the study "Understanding and quantifying the impact of moving target defenses on computer networks." The study, which began in April, will be the first to document whether this type of adaptive cybersecurity, called moving-target defense, can be effective. If it can work, researchers will determine if the benefits of creating a moving-target defense system outweigh the overhead and resources needed to build it.
Helping Ou and DeLoach in their investigation and research are Kansas State University students Rui Zhuang and Su Zhang, both doctoral candidates in computing and information sciences from China, and Alexandru Bardas, doctoral student in computing and information sciences from Romania.
As the study progresses the computer scientists will develop a set of analytical models to determine the effectiveness of a moving-target defense system. They will also create a proof-of-concept system as a way to experiment with the idea in a concrete setting.
"It's important to investigate any scientific evidence that shows that this approach does work so it can be fully researched and developed," DeLoach said. He started collaborating with Ou to apply intelligent adaptive techniques to cybersecurity several years ago after a conversation at a university open house.
The term moving-target defense -- a subarea of adaptive security in the cybersecurity field -- was first coined around 2008, although similar concepts have been proposed and studied since the early 2000s. The idea behind moving-target defense in the context of computer networks is to create a computer network that is no longer static in its configuration. Instead, as a way to thwart cyber attackers, the network automatically and periodically randomizes its configuration through various methods -- such as changing the addresses of software applications on the network; switching between instances of the applications; and changing the location of critical system data.
Ou and DeLoach said the key is to make the network appear to an attacker that it is changing chaotically while to an authorized user the system operates normally.
"If you have a Web server, pretty much anybody in the world can figure out where you are and what software you're running," DeLoach said. "If they know that, they can figure out what vulnerabilities you have. In a typical scenario, attackers scan your system and find out everything they can about your server configuration and what security holes it has. Then they select the best time for them to attack and exploit those security holes in order to do the most damage. This could change that."
Creating a computer network that could automatically detect and defend itself against cyber attacks would substantially increase the security of online data for universities, government departments, corporations and businesses -- all of which have been the targets of large-scale cyber attacks.
In February 2011 it was discovered that the Nasdaq Stock Market's computer network had been infiltrated by hackers. Although federal investigators concluded that it was unlikely the hackers stole any information, the network's security had been left vulnerable for more than a year while the hackers visited it numerous times.
According to Ou, creating a moving-target defense system would shift the power imbalance that currently resides with hackers -- who need only find a single security hole to exploit -- back to the network administrators -- who would have a system that frequently removes whatever security privileges attackers may gain with a new clean slate.
"This is a game-changing idea in cybersecurity," Ou said. "People feel that we are currently losing against online attackers. In order to fundamentally change the cybersecurity landscape and reduce that high risk we need some big, fundamental changes to the way computers and networks are constructed and organized."
Share this story on Facebook, Twitter, and Google:Other social bookmarking and sharing tools:
Story Source:
The above story is reprinted from materials provided by Kansas State University.
Note: Materials may be edited for content and length. For further information, please contact the source cited above.
Note: If no author is given, the source is cited instead.
Disclaimer: Views expressed in this article do not necessarily reflect those of ScienceDaily or its staff.
Tuesday, June 12, 2012
Self-adapting computer network that defends itself against hackers?
Scott DeLoach, professor of computing and information sciences, and Xinming "Simon" Ou, associate professor of computing and information sciences, are researching the feasibility of building a computer network that could protect itself against online attackers by automatically changing its setup and configuration.
DeLoach and Ou were recently awarded a five-year grant of more than $1 million from the Air Force Office of Scientific Research to fund the study "Understanding and quantifying the impact of moving target defenses on computer networks." The study, which began in April, will be the first to document whether this type of adaptive cybersecurity, called moving-target defense, can be effective. If it can work, researchers will determine if the benefits of creating a moving-target defense system outweigh the overhead and resources needed to build it.
Helping Ou and DeLoach in their investigation and research are Kansas State University students Rui Zhuang and Su Zhang, both doctoral candidates in computing and information sciences from China, and Alexandru Bardas, doctoral student in computing and information sciences from Romania.
As the study progresses the computer scientists will develop a set of analytical models to determine the effectiveness of a moving-target defense system. They will also create a proof-of-concept system as a way to experiment with the idea in a concrete setting.
"It's important to investigate any scientific evidence that shows that this approach does work so it can be fully researched and developed," DeLoach said. He started collaborating with Ou to apply intelligent adaptive techniques to cybersecurity several years ago after a conversation at a university open house.
The term moving-target defense -- a subarea of adaptive security in the cybersecurity field -- was first coined around 2008, although similar concepts have been proposed and studied since the early 2000s. The idea behind moving-target defense in the context of computer networks is to create a computer network that is no longer static in its configuration. Instead, as a way to thwart cyber attackers, the network automatically and periodically randomizes its configuration through various methods -- such as changing the addresses of software applications on the network; switching between instances of the applications; and changing the location of critical system data.
Ou and DeLoach said the key is to make the network appear to an attacker that it is changing chaotically while to an authorized user the system operates normally.
"If you have a Web server, pretty much anybody in the world can figure out where you are and what software you're running," DeLoach said. "If they know that, they can figure out what vulnerabilities you have. In a typical scenario, attackers scan your system and find out everything they can about your server configuration and what security holes it has. Then they select the best time for them to attack and exploit those security holes in order to do the most damage. This could change that."
Creating a computer network that could automatically detect and defend itself against cyber attacks would substantially increase the security of online data for universities, government departments, corporations and businesses -- all of which have been the targets of large-scale cyber attacks.
In February 2011 it was discovered that the Nasdaq Stock Market's computer network had been infiltrated by hackers. Although federal investigators concluded that it was unlikely the hackers stole any information, the network's security had been left vulnerable for more than a year while the hackers visited it numerous times.
According to Ou, creating a moving-target defense system would shift the power imbalance that currently resides with hackers -- who need only find a single security hole to exploit -- back to the network administrators -- who would have a system that frequently removes whatever security privileges attackers may gain with a new clean slate.
"This is a game-changing idea in cybersecurity," Ou said. "People feel that we are currently losing against online attackers. In order to fundamentally change the cybersecurity landscape and reduce that high risk we need some big, fundamental changes to the way computers and networks are constructed and organized."
Share this story on Facebook, Twitter, and Google:Other social bookmarking and sharing tools:
Story Source:
The above story is reprinted from materials provided by Kansas State University, via Newswise.
Note: Materials may be edited for content and length. For further information, please contact the source cited above.
Note: If no author is given, the source is cited instead.
Disclaimer: Views expressed in this article do not necessarily reflect those of ScienceDaily or its staff.
Saturday, June 2, 2012
Zappos breach goes beyond credit cards: Consumers face identity theft if hackers correlate other penetrated databases
Wicker conducts research in wireless information networks. He focuses on networking technology, law, and sociology, and how regulation can affect the privacy and speech rights. He is the author of the book "Cellular Convergence and the Death of Privacy," to be published by Oxford University Press at the end of 2012.
He says: "Though Zappos has not stated how security was breached, this event is a reminder that security is not a fix or an overlay, it is an ongoing process that must be intrinsic to the design and maintenance of an Internet presence.
"Zappos said that credit card information was not stolen, but acknowledged that email addresses, billing and shipping addresses, phone numbers, and the last four digits from credit cards may have been compromised. This is a lopsided outcome for the customer.
"The bigger problem Zappos faces is that large databases of consumer information can be used for identity theft. As Zappos acknowledged, users who use the same or similar passwords are at risk of theft through access to other sites such as Amazon or Ebay.
"More generally, information about a customer can be used to 'de-anonymize' other databases on other Web sites, further invading customer privacy. Correlation attacks enabled by such data have been shown to strip anonymity from NetFlix, AOL and other databases that were assumed safe. Thus, the information used can include customer preferences, beliefs and practices that are far harder to change than a credit card number.
"Zappos' response is admirable for its forthrightness and immediacy, but this is a reminder of the risk run when online service providers maintain databases of user data. This is a practice that many, many web site and service providers engage in for convenience and, in some cases, for profit. This is a practice that a networked society cannot afford for the long term if individual privacy is to be preserved."
Share this story on Facebook, Twitter, and Google:Other social bookmarking and sharing tools:
Story Source:
The above story is reprinted from materials provided by Cornell University, via Newswise.
Note: Materials may be edited for content and length. For further information, please contact the source cited above.
Note: If no author is given, the source is cited instead.
Disclaimer: Views expressed in this article do not necessarily reflect those of ScienceDaily or its staff.