no image

Unto the breach

Pro
TechIreland is a not-for-profit, open-access data platform that maps Ireland's technology ecosystem

1 October 2011

IT security threats are nothing new, but developments in the technology and methods used by so called ‘hacktivists’ have proved extremely embarrassing for the organisations that have fallen foul of them.

In the last year alone, dozens of high profile companies and organisations have had their web sites taken down, their customer’s personal details stolen and their public image tarnished. These have included organisations as diverse as Fine Gael and Sony.

The common factor? They both attracted the attention of people who think it’s fun to digitally kick their front door in, trash their offices and spray-paint their walls. Perhaps it’s not surprising that organisations like Anonymous and Lulzsec have chosen to use the Internet to harass their targets, but according to IT security specialists, what is surprising is how easily they’ve been able to bring large companies to their knees.

Keeping up
"Although technology has moved on wonderfully and security products have gotten better and better, the fact of the matter is that we as human beings haven’t kept up," said Graham Cluley, senior technology consultant with security specialist Sophos. "We are still falling for simple tricks or making the same mistakes, like using the same password for multiple different places online. That walks us straight into the arms of the hackers."

 

advertisement



 

Cluley argues that the primary reason companies are left exposed to the kinds of risks posed by organisations like Anonymous and Lulzsec is that they don’t encourage the right kind of awareness throughout their staff. It’s rarely a technology issue.

"Technology and security products can and undoubtedly do reduce your risk of exposure, but ultimately you have to have your staff on board. You have to educate them as to the risks, because otherwise they’ll lead you into danger," he said.

"There are lots of easily available technology that can mitigate risk. For example, you can easily encrypt sensitive data so that even if does fall into the hands of a hacker, they won’t be able to do anything with it. The reality though is that there are many organisations not doing even that."

With some very large and prominent organisations suffering embarrassing security failures-both the CIA in the US and the IMF in Europe have been the victims of attacks-it’s tempting to think that hacktivist groups are able to steamroll through even the most sophisticated security systems. According to Cluley, this isn’t the case.

Power age
"We have to be careful of assuming that these groups are all powerful-they’re not. They find weaknesses in advance and then announce who they’re going to attack based on that, not the other way around. Their threats can also be very vague-threatening countries or industries initially and then targeting only those individual sites or companies that prove attackable."

"Some of these attacks aren’t particularly sophisticated, most notably those from Lulzsec, which have mostly been distributed denial of service (DDOS) attacks, bombarding web sites with traffic. It’s a brute force attack that’s not very elegant and not technically difficult to do, but which can be effective in causing problems."

"In other cases, they’ve found vulnerabilities on web sites that have allowed them to access personal information or information about customers. Again that sounds quite sophisticated, but it’s actually not. It is often the case that the person who wrote the web site left open vulnerabilities on the site that they’re able to exploit."

Inadequacies
Paul C Dwyer, president of the International Cyber Threat Task Force, agrees. "If something positive can be said to have come out of the activities of groups like Anonymous and Lulzsec, it’s that they’ve demonstrated just how inadequate many high profile organisations are when it comes to security," he said.

"There are sophisticated hacks going on out there in the world of industrial espionage, but the mainstream attacks are not sophisticated at all. They are mostly made up of phishing attacks, and the best way to prevent them is user training."

To illustrate his point, Dwyer uses one of the most notorious recent security breaches-when attackers stole information for 40 million two-factor authentication accounts from RSA, the security division of EMC.

"In that case, good old Microsoft Outlook actually detected and quarantined an e-mail that came in that was a cover for a spear phishing attack. This mail had a director’s name in the subject line, and because of that a user decided to open it anyway. It infected the system and caused major problem," he said.

"These types of attacks are based on this kind of behaviour. Hackers use automated tools to scan publicly available IP addresses associated with specific companies-information that is very easy to find. That will tell you very quickly what sort of attacks will likely succeed against that company. It’s not rocket science, and doing this will result in a list of doorways to try."

According to Dwyer, cyber criminals are like normal criminals-they’re not interested in hard work. "Most attacks are the cyber equivalent of petty opportunists walking up a street checking door handles to see which are open," he said. "If you’re sensible, you lock your door."

So what should companies that are concerned about these kinds of vulnerabilities do to ensure they stay safe? Firstly, they need to recognise that there will always be a sliding scale of security.

Mitigation
"Every company has to make a call about how secure they want to be, factored against how much they’re willing to pay and how much inconvenience they’re willing to put up with," said David Keating, security sales manager for Data Solutions.

"You could be 100 per cent sure if you never went on the Internet, but that’s not practical for most companies. At the other extreme, you could just plug into the Net with no security and take your chances. That’s not practical either. Usually people need to feel or see the concrete effects of not having a certain kind of protection in place before they’ll start to take for granted that they need it."

"Initially, the idea of firewalls and anti-spam software were hard sells, but then people started getting spam and random virus attacks, and so it became a given that these things needed to be countered."

Keating suggests that it’s becoming easier all the time for malcontents to create new viruses and other forms of malware, and as a result, security must be seen as an on-going process, not an event in the week or month for the IT department.

"There are toolkits out there now that allow hackers to create these things without having to write them from scratch. Zeus Code is open source and easily available, and they reckon that there are 73,000 new strains of malware being assembled every day. It’s so easy to do that people are able to make them to order and connect them to topical world events, associating them with web sites that are likely to attract traffic, such as those associated the rugby world cup or the royal wedding that took place earlier this year," he said.

"It’s very hard for users to know about all the threats out there, but companies have to keep on top of informing their staff about the way these kinds of attacks happen. There’s a temptation within the IT department to operate security at the network level, but they do need to look at putting it on the desktop as well. This allows the users to flag things they come across that look a bit dodgy."

On the desk
According to Eoin Goulding, managing director of Integrity Solutions, this security on-the-desk idea is crucial, as it illustrates that security is not just a software issue, but also a usage issue.

"The big one right now is web traffic-that’s where most malware comes from. Anti-virus software will scan your e-mail and data sent to you but it doesn’t monitor web traffic. Often people don’t realise that there is stuff being downloaded behind the sites they visit onto their desktop PC," he said.

"We’ve seen lots of cases recently of web ads being used for this purpose, where an advert appears on an otherwise well-regarded or trusted site, but there is code behind the ad. When it’s clicked on, it downloads malware onto the user’s PC that can then jump from that computer to the network and its servers, bypassing your anti-virus software entirely."

"We had a client who came to us when malware got onto their system in this way and it encrypted all their data so they couldn’t get to it. However security isn’t just about minimising the risk of data being stolen, it’s also about network resiliency and minimising the risk of downtime," Goulding said.

"Ask the average CEO how their company would fare without internet or e-mail access for two or three days and watch them go pale. Who can live without those things now? The better your security and the more your network is protected, then the more resilient it’s going to be in general. It also has to be said, that employees do stupid things all the time, clicking on e-mail attachments that they shouldn’t and going to web sites that are a bit dodgy and that are infected with malware, and that has to be dealt with."

Overstatement
Cluley of Sophos thinks that it’s not possible to overstate the importance of attitudes and culture in minimising security risks.

"Culture is incredibly important. You frequently find that even in security conscious organisations there are many staff who will bring in technology from outside such as USB sticks or their own personal laptop or tablet, and connect them to the office network. If you don’t have technology in place inside your organisation to police that kind of activity, then potentially that can be a route for hackers and malware to find its way into your organisation," he said.

"We try to show our clients the value of evangelising security from the top of the organisation down. Sometimes the people at the very top of an organisation are the hardest to get to follow the rules. They’ll be the ones saying, ‘I want to bring my iPad to the office’ or ‘I want to get my e-mail on this device’ or ‘ I want to copy files onto my laptop so I can take them home with me.’"

"They’ll override the security policies to do these things, because they want to and don’t see why they shouldn’t. That’s why you need buy-in from on high-you need to give IT staff the authority to say ‘actually, I’m in charge of security. You may be the CEO but there is a good reason why you put me in this position, and it’s to tell you no, what you’re asking is not in the best interests of your company.’"

"In everyday life, we don’t always like what our doctor has to say to us when we go to visit. We pay them to work for us, but we ignore their advice at our peril, and there is something similar going on in the security department."

Old reliables
On a practical level, Sophos recommends that companies concerned about their security make sure the old reliables are still getting the attention they deserve.

"Make sure you have up to date anti-virus and anti-spam software monitoring what comes into your company. You need to keep that up to date. Every day we see something like 150,000 new unique pieces of malware in our labs-a couple of new ones arrive in every second, 24 hours a day," he said.

"You also need to deal with the elephant in the corner of most security issues – passwords. You need to make sure that staff understands the importance of using different passwords in their work, and that those passwords aren’t easy to crack or guess. There is software to help people remember their passwords if they can’t remember which password is for which use."

"We also recommend people research SQL Injection, a vulnerability that exists on many web sites which allows hackers to access the database running the web site. That may include your customers details-names, dates of birth, credit card information-any information they may have inputted into your site. That’s something to really watch because it’s relatively common."

Read More:


Back to Top ↑