Showing posts with label advanced persistent threats. Show all posts
Showing posts with label advanced persistent threats. Show all posts
Wednesday, February 10, 2016
The Institute for Critical Infrastructure Technology (ICIT) Releases the Encyclopedia of the Most Prominent Hacktivists, Nation State, and Mercenary Hackers
The Institute for Critical Infrastructure Technology, a leading cybersecurity think tank, has published its most recent research report entitled Know Your Enemies 2.0: A Primer on Advanced Persistent Threat Groups. The report is an encyclopedia of bad actors stemming from the nation state, mercenary, and hacktivist arenas and details the characteristics and intricacies of the world’s most prolific threat groups.
Authors James Scott (ICIT Co-Founder and Senior Fellow) and Drew Spaniel (Visiting Scholar) cover threat groups not by use of a particular ranking system, rather by the dominant players categorized by geography, including China, Russia, Iran, and North Korea. Zero days, malware, tool kits, exploit techniques, digital foot prints and targets are covered in-depth. The report covers 40 bad actors including: Blue Termite, the Elderwood Platform, Deep Panda APT 30, APT 2, Tarh Andishan, Ajax, Dark Hotel, Bureau 121, Energetic Bear, Uroburos, Sofacy Group, the “Duke” family, Carbanak, SEA, Animal Farm, Hellsing. and Shrouded.
Monday, May 4, 2015
Fifteen Years After the ILoveYou Bug: Has the Face of Malware Changed?
Where were you when the ILOVEYOU bug started spreading on May 4, 2000, exactly 15 years ago? Was your computer one of the tens of millions of PCs the Love Letter attacked? How has malware changed in the last 15 years? Read on ...
Friday, June 29, 2012
GAO: Cyber Threats Facilitate Ability to Commit Economic Espionage
Another day, another warning, another restatement of the obvious. In the summary, it's noted that in past reports the GAO has made hundreds of recommendations to better protect federal systems, critical infrastructures, and intellectual property. The implication is that prior warnings have gone unheeded, and little's been done about these threats and vulnerabilities from both technology and personnel.
Tuesday, December 6, 2011
Symantec November 2011 Intelligence Report
Symantec released another of its threat reports. I have to admit. I really enjoy reading these. There concise and informative, even if they do occasionally scare the stuffing out of me. Among the findings are the number of daily targeted attacks has increased four-fold compared to January this year; the public sector has been identified as the most frequently targeted industry during 2011, with approximately 20.5 targeted attacks blocked each day; and large enterprises consisting of more than 2,500 employees received the greatest number of attacks.
Friday, December 2, 2011
Symantec's Top Trends in IT Security from 2011 and for 2012
With the end of the year close at hand, Symantec has taken a look back at the top trends in IT security from 2011 that we think will continue throughout 2012. No surprises here. Advance persistent threats and smart mobile devices top the list.
Shameless plea: I'm still looking for someone to write an book about APTs.
Shameless plea: I'm still looking for someone to write an book about APTs.
Friday, October 7, 2011
Cloud Security: Closing the Barn Door after the Horses Have Fled
The GAO says that says that the Feds haven’t done enough about a cloud strategy, including security. Isn’t it too late to worry about that? Enterprises, government, and even individuals, driven by cost considerations and dubious cost/benefit analyses, continue to flock to the cloud regardless of security concerns.
After all, if it’s an Internet-facing application, does it really matter whose application it is or where the data resides? Enterprises haven’t done a great job of protecting data when it’s stored in-house. How can the cloud be any worse?
As Jim Tiller pointed out, there’s a change coming in information security, from protect and detect to respond. Protect isn’t working too well, and detect is too slow, especially in the face of APTs. Attacks are increasingly more sophisticated, whether from governments or organized crime, and data increasingly less secure, regardless of where is resides. The days of reactive security are nigh.
After all, if it’s an Internet-facing application, does it really matter whose application it is or where the data resides? Enterprises haven’t done a great job of protecting data when it’s stored in-house. How can the cloud be any worse?
As Jim Tiller pointed out, there’s a change coming in information security, from protect and detect to respond. Protect isn’t working too well, and detect is too slow, especially in the face of APTs. Attacks are increasingly more sophisticated, whether from governments or organized crime, and data increasingly less secure, regardless of where is resides. The days of reactive security are nigh.
Thursday, September 1, 2011
So, how insightful is this?
CSO magainze has a little piece on a minor hacker who opines that "good liars undermine information security." Okay, so don't liars undermine just about everything?
Thursday, August 18, 2011
... the More Things Stay the Same
Earlier this year I surveyed some authors about what they considered their top 5 information security issues. While there were some surprises, such as supply chains, there was more consensus. Among the top issues are cloud security, malware and advance persistent threats, smart phones and other mobile devises, social media in the workplace, data loss, and critical infrastructure protection and cyberwarfare. As I said, no surprises.
Lately, though, we’ve been reading and hearing in the consumer press about malware, cyberwarfare, tons of data loss, and security and privacy problems with social media as well as more invasive and insidious tracking. So, there’s increasing awareness of these threats by the general population, or should be, and convergence between what they and people working in information security consider risky. Maybe.
There’s a lot of distance between being aware of something and doing something about it. People are still flocking to smart phones and social networking, sharing far too much data and information, and leaving themselves at risk to threats they really don’t appreciate. Ignorance is bliss until calamity strikes, and it will.
Lately, though, we’ve been reading and hearing in the consumer press about malware, cyberwarfare, tons of data loss, and security and privacy problems with social media as well as more invasive and insidious tracking. So, there’s increasing awareness of these threats by the general population, or should be, and convergence between what they and people working in information security consider risky. Maybe.
There’s a lot of distance between being aware of something and doing something about it. People are still flocking to smart phones and social networking, sharing far too much data and information, and leaving themselves at risk to threats they really don’t appreciate. Ignorance is bliss until calamity strikes, and it will.
Wednesday, August 3, 2011
Advanced Persistent Threats: Made in China
RSA released a report on advanced persistent threats. Basically, we're all screwed. This coincides with a story today about Operation Shady RAT, the infiltration of the networks of 72 organizations going back several years. The attacks are attributed to a state actor, China. China seems to be behind all espionage and cyberware attacks, not to mention threats hidden in firmware and other components. I wonder why they're not blamed for financial hacks, too, but that seems to be Russians and Eastern Europeans.
Subscribe to:
Posts (Atom)