Cyber Security - the emerging lifeline

Cyber security is emerging as the life in the digital world.

Management Education

Management education has become critical in this hyper active world filled with dynamics.

Cyber Security training

Cyber security calls for intricate understanding

Police trained in Cyber Security

Cyber Security Calls for a series of awareness programs followed by diploma and degree programs

Cyber World !

Cyber World is composed of various interdependent components.

Showing posts with label Technology. Show all posts
Showing posts with label Technology. Show all posts

Thursday, January 3, 2013

PlugX and its implications

A new Remote Administration Tool has been discovered called PlugX which is a Remote Access Tool (RAT). It has also been named as Korplug. PlugX has been detected in targeted attacks not only against military, government or political organizations, but also against more or less ordinary companies. The attack starts with a phishing email containing a malicious attachment, usually an archived, bundled or specially crafted document that exploits either a vulnerability.

Tuesday, January 1, 2013

Mariposa Botnet


Understanding Bots as a technology has emerged as a critical skill in the information era. This article is focused in understanding Mariposa. Botnet Mariposa was reported by defense intelligence some time during May of 2009. Trend micro says that the worm has been in existence as early as December 2008.

Tuesday, March 20, 2012

Security: Know your APT

Advanced Persistent Threats (APTs) has been estimated to grow faster than other technologies. APT is a a part of the classified category of cyber crime directed at  business at large and / or political targets. They are built with a high degree of stealithiness over a prolonged duration of operation in order to be successful. APTs are built with a fixed goal of remaining invisible as long as possible. As such, tahe APT operators tend to focus on “low volume” attacks and over time they would have covered a large area,  stealthily crawling from one host to the next as it is being compromised., and ensuring to avoid generating regular or predictable network traffic. Damballa predicts that the volume of persistent attacks directed at large corporations will continue to increase and the victims will continue to feel as though they have been specifically targeted in the year 2012. McaFee is clear in commenting that the solutions in silos don’t enrich each other with relevant data and introduce greater complexity to analysis and remediation, giving the advantage to the perpetrators of the APT. 

Security: Know your DNS

The Domain Name System (DNS), has been defined by RFCs 1034 and 1035. It is a  hierarchical, and distributed database used for providing a service to resolve names for various Internet applications. A zone as understood by everybody is a collection of nodes, forming a contiguous tree structure, with  the start of authority, or SOA. The purpose of SOA is to delegate the naming authority downward, to delegation points, terminating with leaf nodes. The elements of the SOA are made available from the DNS authority servers to recursive DNS servers.

Whenever DNS is queried, a resolver will traverse the DNS hierarchy and locates the appropriate authoritative DNS server and gets an answer. The resolver executes recursive queries through the hierarchical tree, and eventually reaches the nameserver that is authoritative for the specified query. Once that server is identified, the answer to the query is retrieved by the resolver, completing its query. The deployed DNS infrastructure supports the query,  of which Address (A) and Pointer (PTR) are the most common deployed queries.


DNS security as a generic term is used to address the following three functions:
  • Zone Transfer Security.
  • Dynamic DNS (DDNS) Security. .
  • Zone Integrity
Of late there appears to be the start of a different  form of attack: the subversion of a host’s correct resolution path. In this attack, the client is directed to use a rogue DNS server, which provides incorrect answers to queries or selective manipulation of answers for the purposes of commercial gain, phishing or other abuse. In most cases, the users have no indication that the DNS answers are not what the correct authoritative DNS servers would provide. A classical example is the Ghost Click described in this blog.

Thursday, March 15, 2012

Digital Warfare - Duqu: Struxnet family of BOTS

Stuxnet, the first military-grade cyberweapon known to the world.  Stuxnet was believed to have been released in late 2009 and millions of computers were infected as the worm though there are other references which claim that it was release as early as 2007. Stuxnet was designed to cripple control systems. The list of modules built as a part of Struxnet provide different kinds of permutations and combinations to reassemble the code with variations. One such example was the birth of Duqu.
Duqu, acts as a Trojan, stealing data, potentially acting in the planning stages of an attack. It can be said that DuQu was used as an intelligence gathering tool, possibly  aiming to prepare the ground for future attacks.  According to Alex Gostev, the main module consists of three components:
  • a driver that injects a DLL into system processes;
  • a DLL that has an additional module and works with the C&C; and
  • a configuration file.


Wednesday, March 14, 2012

Digital Warfare & Struxnet - Where are we in security?

Enisa has come up with a statement that Stuxnet is a specialized malware targeting SCADA systems running Siemens SIMATIC® WinCC or SIMATIC® Siemens STEP 7 software for process visualization and system control.  The software consists of a series of software block, which are combined into a project.Some of the blocks include Function blocks, Operational blocks, and Data blocks. These software system command the components that control speed in gas-enrichment centrifuges, used for separating radioactive isotopes by spinning at supersonic speeds.

Monday, March 12, 2012

BigData & Digital footprint

Big-data is painting the data canvas with novel techniques and methods to handle new forms of business built on predictive intelligence. Going by the statement”Nothing is free in this world” organizations provide certain e-services to capitalize on the fact that  if a customer is not paying for service, then he is the product who can be used to leverage the existing business. Customers at large including free users have chiseled their digital footprints which were hitherto ignored. Thanks to the emergence of big data; the values of such digital footprints have been recognized. Going by the law of survival, when left in wild, there is a need to establish and track the digital footprints in order to profile the customer base. Big data analytic is emerging as a digital foot print tracker and modeler to provide the razor sharp strategic edge for organizations to leverage their existing business and cross pollinate.

Sunday, February 19, 2012

Big Data association and aggregation


Organizations are dependent on Information technology, They are forced to collect information as a part of their day to day electronic transactions. Such collected information silos are scattered across various cooperating and independent organizations. Management models have evolved into collaborative business models leading to a win win for member or partners of the coalition. Such organizations with excellent chemistry have exercised partnerships to exploit their combined strength to win. These firms include, enterprises, large organizations and government departments have aggregated volumes of data on individuals, spread across their verticals, profiled individuals, and are today looking for synergies and opportunities for cross-fertilization leading to better insight and better business. Such firms churn data with a greater velocity and variability through the multitudinous elements composing the business canvas.

Apart from the operational data addressing the IT systems, which are internal, customer centric data from elements like blogs, social media networks, and location based services, browser based data, which impact the business portfolio and provide business variations in terms of USP to the respective firms are generating valuable insight on customer profiling. Adding fuel to this is the dynamic business environment shifting gears to consolidation and Cloud computing where data could be aggregated. For example cloud oriented and / or localized application and infrastructure events provide a real time insight on usage patterns. Such events governed by SIEM modeling methods  would benefit on Big-data. For example, ATM transactions are profiled to manage location based profiling, which can trigger on abnormalities and throw additional checks. For example, social network and blog entries have come up with their specific search engines to analyze data in real-time. If such aggregated data could be exploited to trigger on data-patterns, organizations would be in a position react with appropriate change management initiatives. On a parallel lookout this is similar to the established just-in-time strategy with the difference being micro managed scope of coverage.

Author - IT for Management, Oxford Press

Friday, February 10, 2012

MoneyWise-Topline and Bottom line

Information technology (IT) is today woven into our daily life. In a globalized economy, business life without informational technology driven applications would be impossible transforming information technology as a commodity. From a niche market, information technology has evolved into a commodity market. In order to sustain, information technology is envisaged to create value.  Today business with information technology is adopting bottom-line strategy to increase efficiency by reducing overall costs and top-line strategy to generate new revenue through new products and services.


Tuesday, January 24, 2012

What is Big data


Shopping habits reveal even the most personal information.  All major retailer vendors from investment banks, to sim card vendors, to grocery chains, bankers today is moving with a “predictive analytics” department specialized to comprehend the consumers’ shopping habits including their personal habits, to customize their marketing methods. For example Target a retail unit was able to predict based on the buying pattern,  that a  teenage shopper was pregnant before her dad did. The high school student’s father was furious as he stormed  into a Minneapolis-area store clutching coupons sent to his daughter for maternity and baby products. Such is the power of Data analytics.

Such data provide enough digital footprints for any interested party to do a follow-up. Going by the modern management theory of providing the customer with what he wants,  it is essential to understand what he wants. Though the data was being collected all along, Information technology was unable to handle provide an edge to business in terms of data analytics.

Is it only marketing.The answer is a definite NO. There are other areas of overlap which is attracting the attention of Management. Some of the other areas include, Security and Information Event Management which is a huge area of concern. The SIEM has started throwing digital foot prints on the application usage pattern of potential customers in terms of handling operating system and other applications which site on top of OS. Technologies like  SNMP  and RMON are capable of pushing specialized data to the external world which provides excellent insight.

Author-It for Management,Oxford Press

Sunday, October 16, 2011

Need for 2 Factor Authentication

Cyber Society of India had organized an media awareness workshop on Saturday the 15th October 2011 at Chennai Press Club. The workshop was inaugurated by Dr.Santhosh Babu, IAS, IT secretary to Government of Tamilnadu,  More than 30 media professionals participated.

I had an opportunity to address the gathering on the need for 2 factor authentication in bank transactions. Predominantly twin passphrase 2FA is used by banks. The concept of one time password  has not been understood by and large. One Time Password system as a second factor authentication increases the transaction safety for netizens. There are different variations of 2FA currently available in the market. The form factor varies from hard tokens to soft tokens. The soft token deployment is aimed at cell phones, laptops and ipads which is a common gadget available with an average citizen. There are other benefits like the ease of deployment and management. The Soft 2FA tokens also reduces the cost to consumer.

The program was over by around 2PM