Wednesday, July 27, 2011

Article on Increasing Rate of Cyberattacks

Just got the IEEE Spectrum Magazine July 2011 issue in the mail yesterday. When I started reading it, I noticed a short but interesting article on page 8 in the "Spectral Line" column by Robert N. Charette. The article titled as "More Cyberattacks or Just More Media Attention?" I found the following parts from the article interesting:

"The Internet was not built with security in mind. Regrettably, most IT systems and application that connect to the Internet were not developed with security in mind either, nor has there been much incentive to do so."

In my opinion, this statement is right on. It is unfortunate that majority of organizations out there are still dealing with proper implementation of fundamental security controls. I recognize that there are pretty sophisticated attacks and intrusions going on "out there" as well. However, I still believe that a good percentage of organizations are still struggling with implementing basic security controls. On the other hand, perhaps, the management at those organizations are taking way too much risk with respect to security. I know that nothing comes free and every security control have a price tag. However, these days, consequences of security incidents are very serious. Sometimes, a security incident can create some much damage at the company's reputation and that can lead to a path to complete collapse for the company. This brings the importance of having a management with good understanding of risks associated with not implementation certain security controls. ISACA's RiskIT framework comes to my mind as a resource to educate the management about risk.

The article ends with the following two sentences:
"...cyberattacks are just the risk of doing business. Sadly, only when the risk of cyberattacks becomes unaffordable will cybersecurity be taken seriously.

I believe that the risk of cyber attacks for some organizations has already become unaffordable. The management for the organizations in the industries like banking, security, government should pay careful attention to the risk with respect to the cyber attacks.

The complete article can be found at this link: http://spectrum.ieee.org/computing/networks/more-cyberattacks-or-just-more-media-attention

P.S. Although it might be redundant but I still would like to mention that IEEE creates such a high quality content within its publications. I am a proud member of IEEE. Way to go, IEEE...

Sunday, February 13, 2011

Airport Security

When I have time, I would like to write a fairly long article on this topic but for now, I want to share a couple of quotes from the article "The Security We Want" by Glenn Harlan Reynolds, published in Popular Mechanics magazine February 2011 issue:

- "The Israelis focus on the person, looking for signs of nervousness, stories that don't hang together and other evidence of nefarious intent. This makes sense. Ultimately, it's people, not objects, who pose the danger."

-"Security has always been about everyone, not just the professionals, because where terrorism is concerned, everyone is on the front line."

- "To fight terrorism, we need a populace that is informed, motivated, vigilant and prepared, not one that is seething and feeling powerless and resentful."

Of course, some companies are also making fun of the current airport security situation in their commercials as well:
Here is another one from NFL:

Sunday, January 16, 2011

"The Third Phase of the Web"

I would like to share an interesting small part of the Social Networking article (page 33) from the January 2011 issue of IEEE Spectrum Magazine:

"We are heading into a third phase of the Web" by Joe Stump (CTO of SimpleGeo)

"The webs between humans and machines, and between humans and the people they trust, have already been spun. The Web of the future will instead connect our physical world with our virtual one, enabling our online social interactions to give us valuable insights into our off-line lives." by Ariel Bleicher

For the complete article, please take a look at this link:
http://spectrum.ieee.org/static/special-report-top-11-technologies-of-the-decade

Friday, December 17, 2010

Open Source Security Testing Methodology Manual

The version 3 of OSSTMM  (Open Source Security Testing Methodology Manual) has been published at this link:

http://www.isecom.org/mirror/OSSTMM.3.pdf 

Happy reading.

Thursday, October 14, 2010

"Cyber Armageddon" by Robert W. Lucky

While I was reading the reflections column in the IEEE Spectrum magazine's September 2010 issue, I noticed some intresting perspectives. I am basically listing my highlighted lines from the article:
  • "Intelligent Risk Management"
  • "Moreover, an insider isn't just a systems administrator; it's anyone or anything that touches your network, including all the equipment and the whole supply chain behind it. All it takes is one employee using the same USB drive on two different networks—the IT equivalent of a surgeon not washing his hands between operations—to fatally compromise a system's security."
  • "If your data is valuable enough, there is almost nothing you can do to provide total security against an expert adversary."
  • "The Internet itself has proven resilient, and though parts of it can go down, the organic growth of pathways and the diversity of equipment provide enormous robustness."
  • " I think that any objective analysis of the situation would conclude that perfect security is not possible, other than through the draconian proposition of complete isolation from networks."
To read the whole article, please visit: http://spectrum.ieee.org/telecom/security/cyber-armageddon 

Friday, March 26, 2010

Usability vs Security vs Operability

From a security perspective, the weakest links in the chain are usually the human beings. The end-users' security posture can be dramatically increased by providing simple but continuous security awareness training. The service providers (i.e., banks, government institutions, online-shopping sites) can support this important cause by funding the centralized or distributed security awareness and training initiatives. I think that within the last 10 years (based on my personal observation), there is an increased level of awareness among the end-user community. For the attacks targeting end-users, the attacker community's target is to gather all the "low hanging fruits".


I also want to point out that the technology plays an important role in enabling secure communication between the end-users and the service providers. The password-based authentication is still the main type of authentication used in the real world. Although we know that the security research community came up with 2-factor, 3-factor, (even 4th-factor authentication has been proposed recently http://www.rsa.com/rsalabs/staff/bios/ajuels/publications/fourth-factor/ccs084-juels.pdf), but the reality is that only few government and enterprise organizations adopt the usage of 2 factor authentication for online-access. Majority of the service providers continue using the password based authentication. We need to think about why there is such a low adoption rate for the advanced authentication techniques. I think that the answer lies within the delicate balance between these three properties: usability, security, and operability. Of course, the businesses make their decisions mainly based on how they decide to handle the risk and the return on security investment.

For example, the biometric authentication gained momentum around 2001/2002 but there is certainly some hesitation towards the biometric authentication from the public and the privacy professionals. PKI based digital certificate authentication, for example, can provide non-invasive 2 factor authentication but maintaining the required infrastructure and managing the keys are quite complicated. Implementations of theoretical security ideas sometimes are taking way too long time to produce mature products. Also, I believe that there are still so many companies out there struggling with implementing and keeping up with the basic security measures.

Friday, March 19, 2010

Sunday, March 14, 2010

The Quantitative Risk Assessment

Question:
"Do you have any quantitative method for evaluating inherent risk, during a risk assessment ? I use a qualitative one that use the results of brainstorming session with head of function."

My Answer:
The quantitative risk assessment is still an open problem in the information security academic research. ( http://archive.cra.org/reports/trustworthy.computing.pdf )

Although there has been some work since 2003 on this challenge,  I think that it still exist today and it is a very difficult problem to solve.