The Best Choice In Property Agent 2013 Awarded by Indonesian Government
New Products
Tampilkan postingan dengan label cyber attacks. Tampilkan semua postingan
Tampilkan postingan dengan label cyber attacks. Tampilkan semua postingan

Jumat, 28 September 2012

Fact-checking the Iranian DDoS Attacks Against US Banks

There's a boat-load of misinformation being dispensed by CNN and Bloomberg about the DDoS attacks targeting our largest U.S. banks. Since this involves erroneous quotes from certain cyber security executives along with a U.S. Senator, I think a little fact-checking is in order.

Bloomberg: "Cyber attacks on the biggest U.S. banks, including JPMorgan Chase & Co. (JPM) and Wells Fargo (WFC) & Co., have breached some of the nation’s most advanced computer defenses and exposed the vulnerability of its infrastructure, said cybersecurity specialists tracking the assaults."

FALSE. This was a Distributed Denial of Service (DDOS) attack. Nothing was "breached". The web servers which hosted the banks' online services were overwhelmed by "calls" and couldn't handle them all.

Bloomberg: "Such a sustained network attack ranks among the worst-case scenarios envisioned by the National Security Agency, according to the U.S. official, who asked not to be identified because he isn’t authorized to speak publicly."

FALSE. There's no one that I know at the NSA (past or present) who believes that customer inconvenience resulting from a DDOS attack against their bank's website is a "worst-case scenario". That's utterly ridiculous.

Bloomberg: "The initial planning for the assault pre-dated the video controversy, making it less likely that it inspired the attacks, according to (Dmitri) Alperovitch and (Rodney) Joffe, both of whom have been tracking the incidents. A significant amount of planning and preparation went into the attacks, they said. “The ground work was done to infect systems and produce an infrastructure capable of launching an attack when it was needed,” Joffe said."

CNN: "To get hold of all the servers necessary to launch such huge attacks, the organizers needed to plan for months, Alperovitch said. The servers had to be compromised and linked together into a network called a "botnet."

FALSE. This attack did not take months to plan for two reasons: 1) This was a crowd-sourced opt-in botnet commonly used in social activism (aka hacktivist) attacks, and 2) No one needs to create a botnet from scratch anymore. You can find them to rent on pretty much any hacker forum world-wide.

CNN: "Sen. Joe Lieberman, an Independent from Connecticut, said in a C-SPAN interview on Wednesday that he believed the attacks were launched by Iran.
"I don't believe these were just hackers who were skilled enough to cause disruption of the websites," he said. "I think this was done by Iran ... and I believe it was a response to the increasingly strong economic sanctions that the United States and our European allies have put on Iranian financial institutions."

BULLSHIT.  There are lots of good reasons for tensions to exist between Iran and the U.S. but this isn't one of them. If you read the excellent open source analysis done by Dancho Danchev you'll see that this was nothing more than Islamic activists protesting the "Innocence of Muslims" video.

Paste bin notice by Qassam Cyber Fighters group
If Senator Lieberman thought this would be a good opportunity to do some Iran-bashing in order to drum up support for his cyber security legislation, he mis-calculated. This statement by the Senator only serves to reinforce the feeling by many that Congress is out of touch with the problem and is in no position to create new cyber security controls or policies.
Add to Cart View detail

Jumat, 10 Agustus 2012

Disruption from Within - the Insider Threat

The publicity, focus and funding associated with advanced persistent attacks and other external threats have left many companies ill prepared to defend against another vector of attack, one that operates below the radar and whose impact can rival that of any external attack - a compromised employee, vendor, supplier - the Insider Theat. Why is it increasing, sometimes  forgotten and how best to protect against it.

I'm pleased to announce that one of the telecommunications industry's leading security professionals will present just such an attack scenario at Suits and Spooks Boston. Henry Shiembob is the Executive Director of Cyber Security and Fraud Operation for Verizon and has responsibility for all global activities related to cyber compliance and investigations, insider threat, supply chain security and external fraud investigations.  Prior to his current role, Henry was Executive Director of International Security for Verizon where he was responsible for all security operations outside the United States; including investigations, physical security, crisis management and executive protection.  Henry also served as the responsible compliance executive for all international operations.

Henry’s career includes over 23 years in risk management, cyber security and international operations, including five years with Kissinger & Associates where he was Team Leader for former Secretary-of-State Dr. Henry A. Kissinger. In this capacity, he directed domestic and international security operations, including risk assessments, executive protection and intelligence briefings and was a government liaison for security matters.

This is one of 15 different offensive talks that you'll hear on October 18th and our attendance will be kept to no more than 130 people to give you ample opportunity to interact with all of our speakers while you're there. If you want to hear and discuss this particular offensive tactic with Mr. Shiembob, then register for Suits and Spooks Boston today. 
Add to Cart View detail

Senin, 23 Juli 2012

Learn how to Take Down a State's Power Grid, Transportation System, and Other Critical Infrastructure

President Obama wrote an Op-Ed piece for the Wall Street Journal last Friday which described a catastrophic attack against the transportation and water sectors of our nation's critical infrastructure. He then pressed for passage of comprehensive cyber security legislation. While Congress and the White House have a sense of what might occur, they don't seem to be aware of the technical vulnerabilities involved or they would know that none of the current cyber security bills pending in Congress could stop such an attack even if they were enacted into law.


Therefore I've decided to invite some of the world's leading experts in protecting critical infrastructure to present how they would mount an offensive attack against their respective industry sectors at the next Suits and Spooks anti-conference to be held October 18th, 2012 in Brookline, MA. For obvious reasons, this event will be closed to the press and none of the presentations will be made public. 


One of our speakers will be Dale Peterson, the founder of Digital Bond, Inc., a control system consulting and research firm that also hosts the most visited SCADA security site and the S4 conference. He began work on control system security in 2000 after beginning his security career as an NSA cryptanalyst. In his presentation for Suits and Spooks Boston, Dale will provide detailed scenarios on how how an adversary would take out thousands of power plants around the world or large parts of the electric transmission system. 


Another one of our speakers will be Rob DuBois, a retired U.S. Navy SEAL and current manager for Red Team operations at a U.S. defense contractor. Since the threats aren't only digital, Rob will walk the audience through how a highly trained team would mount a physical attack against a key facility.


Our keynote speaker will be Dr. David A. Bray who currently serves as Principal Strategist and Senior National Intelligence Service Executive with the National Commission for Review of Research and Development Programs of the U.S. Intelligence Community. Prior to joining ISE, Dr. Bray served as a strategist at the Institute for Defense Analyses and the Science and Technology Policy Institute. In 2009, he deployed to Afghanistan as a Special Advisor to STRATEGIC EFFECTS for NATO’s International Security Assistance Force and U.S. Forces Afghanistan, with the task of helping to “think differently” on critical strategic efforts. Dr. Bray also served as IT Chief for the Bioterrorism Preparedness and Response Program at the U.S. Centers for Disease Control and Prevention, where he led the technology aspects of the bioterrorism program’s response to 9/11, anthrax in 2001, SARS, and other outbreaks. 


This will be the fourth Suits and Spooks event since I first started holding them in September of 2011 and it may be the most critical one yet. The information that will be shared on October 18th by our speakers (a complete list is available at the website) will clearly lay out offensive options that could wreak havoc on up to six key components of critical infrastructure - water, power, transportation, communication, health care, and banking. Due to the timeliness and the importance of this topic, we're going to cap attendance at 130 instead of 100. If you'd like to be part of this history-making event, registration begins today.

Add to Cart View detail

Most View Product

Contact Online

Support : Copyright © 2011. Demo Template AGC - All Rights Reserved
Template Clone Script ID