Showing posts with label threats to information security. Show all posts
Showing posts with label threats to information security. Show all posts

Friday, September 09, 2011

Cyber Crime:Threats to VoIP and Mobile Convergence


The cell phone is getting an completely new tool—
especially outside the U.S., in which accessing the Internet from a cellular device can offer a much better experience than traditional fixed computing. VoIP technology also continues to increase and will rival landline and mobile communications in terms of reliability and call quality.
As Internet telephony and cellular computing handle more and much more data, they will turn into far more frequent targets of cyber crime.

From the outset, VoIP infrastructure has been vulnerable to the same sorts of attacks that plague other networked computing architectures. As soon as voice is digitized, encoded,compressed into packets and exchanged more than IP networks, it's susceptible to misuse.
Cyber criminals will be drawn towards the VoIP medium to engage in voice fraud, data
theft and other scams—similar towards issues email has experienced.
Denial of service, remote code execution and botnets all apply to VoIP networks, and will become more problematic for mobile devices as well.
“Criminals know that VoIP can be applied in scams to steal individual and financial |facts so voice spam and voice phishing aren't heading away” stated Tom

“Most men and women have been trained to enter social security numbers, credit card numbers, bank account numbers, etc. more than the phone even though interacting with voice response systems,” stated Cross.

“Criminals will exploit this social conditioning to perpetrate voice phishing and identity theft. At the same time, consumers wil demand far better availability from phone program than they would from an ISP, so the threat of the DoS attack might compel carriers to pay out over a blackmail scam.”

Tom Cross - X-Force Researcher, IBM World-wide-web Security Systems
“At this point, mobile device potential is far ahead of security,” mentioned Traynor. “We’ll begin to determine the botnet problem infiltrate the mobile world in 2009.”
Patrick Traynor - Assistant Professor, School of Computer Science at Georgia Tech,
and member in the Georgia Tech Facts Security Center Cross,a researcher on the IBM Web Security Systems X-Force team. “Denial of program will also continue to be a critical threat to VoIP. If a big number of VoIP phones become infected by malware and flood a network with traffic, the results could be extremely disruptive. 
We expect some cyber criminals to attempt to blackmail
carriers based on a DoS attack scenario.”

According to Cross, large telecom corporations in Europe are now servicing clients  with VoIP. And where phone service is concerned, users have one more mentality about sharing individual information and also a higher expectation of quality.
On the bright side, Cross believes the IT and telecom communities have learned valuable security lessons from the spam and phishing problems that have plagued the
Simple Mail Transfer Protocol (SMTP).

“VoIP providers and users would like to avoid the spam crisis that has inundated email,” said Cross.
“Current research efforts at university-based centers like GTISC are studying how popularity networks according to inherited trust could be applied to VoIP to prevent voice fraud. In this kind of system, good security reputations will improve VoIP peering and call ranking so that legitimate calls get through, and voice spam and phishing are blocked.”

Cross also cited the need for intrusion prevention systems at the VoIP carrier level, along with endpoint security for Session Initiated Protocol (SIP) phones and other VoIP devices.
“While exploits targeting the iPhone have circulated publicly, I’m somewhat surprised that there haven’t been more attacks to date,” mentioned Cross.

Dave Amster, vice president of security investigations for Equifax also sees the security challenges presented by mobile computing. “More and more financial transactions
will take place more than cellular devices,” stated Amster.
“Consumers are ordering credit reports from their Blackberrys, which puts valuable information at risk.
The challenge for businesses and banks will be maintaining secure mobile applications and ease of use at the exact same time.”
 Already in Japan, people use their cell phones at vending machines and subway
token dispensers.

According to Traynor, “malware will be injected onto cell phones to turn them into bots. Large mobile botnets could then be used to perpetrate a DoS attack against
the core in the mobile network.
But due to the fact the mobile communications field is evolving so quickly, it presents
a certain opportunity to model security properly—an opportunity we missed in the PC.”
 “However, it's not going to be an easy trouble to solve.

Traynor pointed to battery power like a principal security hurdle, “If you place antivirus software on the mobile device, it will run the battery down, so cellular security will require new approaches and partnerships between manufacturers, carriers and software developers.”

Friday, August 26, 2011

Cyber Threats report 2009:Emerging threats for…all data-driven!(2)


Emerging threats for…all data-driven!

BOTNETS

Most botnet command and manage websites is also traced back to China2. But Lee cautions that this statistic could be misinterpreted since "a good deal of Chinese are usingpirated software program which doesn’t receive security updates.”

According to Lee, “That techniques numerous Chinese computers are rife with vulnerabilities, doing them a haven for botnet command and manage sites.”
Botnets en masse are considered a bot army and these malicious computing forces could be applied to conduct cyber warfare within the future.

In addition, bot payloads are becoming increasingly complex to avoid evolving security measures.
According to Lee’s research at GTISC, several recent bot variants have exhibited more than 100 distinct binary payloads used to hide the communications path and to vary the command and manage IP address. The net effect creates botnets and bot masters harder to track.

However, new technologies can pinpoint the Internet communications among botnets and bot masters and
shut down the vital links required for cyber crime and cyber warfare. Signature-based defenses like antivirus
and intrusion detection are no match to your subtle communications between bot and bot master.
But newer behavior analysis approaches can support identify bots without signatures.

Lee’s search team at GTISC is developing algorithms to analyze targeted visitors patterns from internal machines to outside machines. Strange anomalies in connection duration, time of day, or type of information uploaded/downloaded can indicate a botnet command and control attempt. Lee’s research also examines how botnets use the internet infrastructure.
For example, look-up requests to DNS servers may perhaps provide information on which domain is applied for botnet communications. In addtion, global sensor networks are now using specialized algorithms to pinpoint bot army communications.
Once the command and control links are observed and disrupted, the bot army threat can be neutralized as long as layered security is already in location
Related Articles:
Cyber Crime:Threats to VoIP and Mobile Convergence...

Cyber Threats report 2009:Emerging threats for…all data-driven!




Emerging threats for…all data-driven!


BOTNETS

In 2008, botnets have turn into worse—a trend expected to continue following year.
GTISC estimated in last year’s report that 10 percent of on-line computers have been component of botnets,groups of computers infected with malicious code and unknowingly controlled by a malicious master.
This year, GTISC researchers estimate that botnet-affected machines may comprise 15 percent of on-line computers.

“Compared with viruses and spam, botnets are growing at a faster rate,” mentioned Wenke Lee, an associate professor at GTISC along with a leading botnet researcher. Lee cites three unavoidable factors which are spurring botnet growth:
Infection can occur even through legitimate Web sites
• Bot exploits/malware delivery mechanismsnare gaining sophistication and better obfuscation techniques
• Users don't need to do anything to become infected; simply rendering a Web page can launch a botnet exploit

Bots can also be delivered to a machine in a variety of ways—
via Trojans, emails, an unauthorized instant message client or an infected Internet site. Once installed, bots lie low to avoid notice by antivirus and anti-spyware technology.
Periodically, the bot communicates to a “command and control” server and waits for your response.

The communication— using the command and manage server as an intermediary—can preserve the malicious bot master’s identity hidden.
Lee issues out the distinction among botnets and malware: “What we think of as malware can be responsible for turning a machine into a bot,” mentioned Lee.
“But conventional malware is often a single-purpose attack.

A bot really remains over a machine, maintains a command and manage mechanism to enable communication with the bot master, and can update itself based on people communications. 
The updates enable new bot communication and malicious capabilities, and are often applied to avoid detection.”

Bot communications are designed to seem like normal (Web) targeted visitors using accepted ports, so even firewalls and intrusion prevention systems have a tough time isolating bot messages.
Lee agreed, “It’s incredibly tough to filter bot traffic at the network edge since it uses http and every
enterprise allows http traffic.”

Prompted to act in unison, bots turn into bot armies that harness considerable computing power to engage in a
variety of malicious activities, including:
Information theft (social security numbers, credit card information, trade secrets, etc.)
— Denial of program attacks
— Spam delivery
— DNS server spoofing

According to a report compiled by Panda Labs, in 2Q 2008, 10 million bot computers had been applied to distribute spam and malware across the internet every day1.
Damballa continues to find that 3-5 percent of enterprise assets are compromised on average by targeted
threats for instance bots—even during the presence in the best and most up-to-date security.
Leading industry analysts predict this range to be even higher.

 
Design by Wordpress Theme | Bloggerized by Free Blogger Templates | coupon codes