A new Remote Administration Tool has been discovered called PlugX which is a Remote Access Tool (RAT). It has also been named as Korplug. PlugX has been detected in targeted attacks not only against military,
government or political organizations, but also against more or less
ordinary companies. The attack starts with a phishing email containing a malicious
attachment, usually an archived, bundled or specially crafted document
that exploits either a vulnerability.
Showing posts with label Technology. Show all posts
Showing posts with label Technology. Show all posts
Thursday, January 3, 2013
Tuesday, January 1, 2013
Mariposa Botnet
Labels:
BOTS,
Security,
Technology
Tuesday, March 20, 2012
Security: Know your APT
Advanced Persistent Threats (APTs) has been estimated to grow faster than other technologies. APT is a a part of the classified category of cyber crime directed at business at large and / or political targets. They are built with a high degree of stealithiness over a prolonged duration of operation in order to be successful. APTs are built with a fixed goal of remaining invisible as long as possible. As such, tahe APT operators tend to focus on “low volume” attacks and over time they would have covered a large area, stealthily crawling from one host to the next as it is being compromised., and ensuring to avoid generating regular or predictable network traffic. Damballa predicts that the volume of persistent attacks directed at large corporations will continue to increase and the victims will continue to feel as though they have been specifically targeted in the year 2012. McaFee is clear in commenting that the solutions in silos don’t enrich each other with relevant data and introduce greater complexity to analysis and remediation, giving the advantage to the perpetrators of the APT.
Labels:
Security,
Technology
Security: Know your DNS
The Domain Name System (DNS), has been defined by RFCs 1034 and 1035. It is a hierarchical, and distributed database used for providing a service to resolve names for various Internet applications. A zone as understood by everybody is a collection of nodes, forming a contiguous tree structure, with the start of authority, or SOA. The purpose of SOA is to delegate the naming authority downward, to delegation points, terminating with leaf nodes. The elements of the SOA are made available from the DNS authority servers to recursive DNS servers.
Whenever DNS is queried, a resolver will traverse the DNS hierarchy and locates the appropriate authoritative DNS server and gets an answer. The resolver executes recursive queries through the hierarchical tree, and eventually reaches the nameserver that is authoritative for the specified query. Once that server is identified, the answer to the query is retrieved by the resolver, completing its query. The deployed DNS infrastructure supports the query, of which Address (A) and Pointer (PTR) are the most common deployed queries.
Whenever DNS is queried, a resolver will traverse the DNS hierarchy and locates the appropriate authoritative DNS server and gets an answer. The resolver executes recursive queries through the hierarchical tree, and eventually reaches the nameserver that is authoritative for the specified query. Once that server is identified, the answer to the query is retrieved by the resolver, completing its query. The deployed DNS infrastructure supports the query, of which Address (A) and Pointer (PTR) are the most common deployed queries.
DNS security as a generic term is used to address the following three functions:
- Zone Transfer Security.
- Dynamic DNS (DDNS) Security. .
- Zone Integrity
Of late there appears to be the start of a different form of attack: the subversion of a host’s correct resolution path. In this attack, the client is directed to use a rogue DNS server, which provides incorrect answers to queries or selective manipulation of answers for the purposes of commercial gain, phishing or other abuse. In most cases, the users have no indication that the DNS answers are not what the correct authoritative DNS servers would provide. A classical example is the Ghost Click described in this blog.
Labels:
BOTS,
Security,
Technology
Thursday, March 15, 2012
Digital Warfare - Duqu: Struxnet family of BOTS
Duqu, acts as a Trojan, stealing data, potentially acting in the planning stages of an attack. It can be said that DuQu was used as an intelligence gathering tool, possibly aiming to prepare the ground for future attacks. According to Alex Gostev, the main module consists of three components:
- a driver that injects a DLL into system processes;
- a DLL that has an additional module and works with the C&C; and
- a configuration file.
Labels:
BOTS,
Security,
Technology
Wednesday, March 14, 2012
Digital Warfare & Struxnet - Where are we in security?
Labels:
BOTS,
Security,
Technology
Monday, March 12, 2012
BigData & Digital footprint
Big-data is painting the data canvas with novel techniques and methods to handle new forms of business built on predictive intelligence. Going by the statement”Nothing is free in this world” organizations provide certain e-services to capitalize on the fact that if a customer is not paying for service, then he is the product who can be used to leverage the existing business. Customers at large including free users have chiseled their digital footprints which were hitherto ignored. Thanks to the emergence of big data; the values of such digital footprints have been recognized. Going by the law of survival, when left in wild, there is a need to establish and track the digital footprints in order to profile the customer base. Big data analytic is emerging as a digital foot print tracker and modeler to provide the razor sharp strategic edge for organizations to leverage their existing business and cross pollinate.
Labels:
Management,
Technology
Sunday, February 19, 2012
Big Data association and aggregation
Organizations are dependent on Information technology, They are forced to collect information as a part of their day to day electronic transactions. Such collected information silos are scattered across various cooperating and independent organizations. Management models have evolved into collaborative business models leading to a win win for member or partners of the coalition. Such organizations with excellent chemistry have exercised partnerships to exploit their combined strength to win. These firms include, enterprises, large organizations and government departments have aggregated volumes of data on individuals, spread across their verticals, profiled individuals, and are today looking for synergies and opportunities for cross-fertilization leading to better insight and better business. Such firms churn data with a greater velocity and variability through the multitudinous elements composing the business canvas.
Apart from the operational data addressing the IT systems, which are internal, customer centric data from elements like blogs, social media networks, and location based services, browser based data, which impact the business portfolio and provide business variations in terms of USP to the respective firms are generating valuable insight on customer profiling. Adding fuel to this is the dynamic business environment shifting gears to consolidation and Cloud computing where data could be aggregated. For example cloud oriented and / or localized application and infrastructure events provide a real time insight on usage patterns. Such events governed by SIEM modeling methods would benefit on Big-data. For example, ATM transactions are profiled to manage location based profiling, which can trigger on abnormalities and throw additional checks. For example, social network and blog entries have come up with their specific search engines to analyze data in real-time. If such aggregated data could be exploited to trigger on data-patterns, organizations would be in a position react with appropriate change management initiatives. On a parallel lookout this is similar to the established just-in-time strategy with the difference being micro managed scope of coverage.
Author - IT for Management, Oxford Press
Labels:
Bigdata,
Management,
Technology
Friday, February 10, 2012
MoneyWise-Topline and Bottom line
Information technology (IT) is today woven into our daily life. In a globalized economy, business life without informational technology driven applications would be impossible transforming information technology as a commodity. From a niche market, information technology has evolved into a commodity market. In order to sustain, information technology is envisaged to create value. Today business with information technology is adopting bottom-line strategy to increase efficiency by reducing overall costs and top-line strategy to generate new revenue through new products and services.
Labels:
Management,
Technology
Tuesday, January 24, 2012
What is Big data
Shopping habits reveal even the most personal information. All major retailer vendors from investment banks, to sim card vendors, to grocery chains, bankers today is moving with a “predictive analytics” department specialized to comprehend the consumers’ shopping habits including their personal habits, to customize their marketing methods. For example Target a retail unit was able to predict based on the buying pattern, that a teenage shopper was pregnant before her dad did. The high school student’s father was furious as he stormed into a Minneapolis-area store clutching coupons sent to his daughter for maternity and baby products. Such is the power of Data analytics.
Such data provide enough digital footprints for any interested party to do a follow-up. Going by the modern management theory of providing the customer with what he wants, it is essential to understand what he wants. Though the data was being collected all along, Information technology was unable to handle provide an edge to business in terms of data analytics.
Is it only marketing.The answer is a definite NO. There are other areas of overlap which is attracting the attention of Management. Some of the other areas include, Security and Information Event Management which is a huge area of concern. The SIEM has started throwing digital foot prints on the application usage pattern of potential customers in terms of handling operating system and other applications which site on top of OS. Technologies like SNMP and RMON are capable of pushing specialized data to the external world which provides excellent insight.
Author-It for Management,Oxford Press
Labels:
Bigdata,
Management,
Technology
Sunday, October 16, 2011
Need for 2 Factor Authentication
Cyber Society of India had organized an media awareness workshop on Saturday the 15th October 2011 at Chennai Press Club. The workshop was inaugurated by Dr.Santhosh Babu, IAS, IT secretary to Government of Tamilnadu, More than 30 media professionals participated.
I had an opportunity to address the gathering on the need for 2 factor authentication in bank transactions. Predominantly twin passphrase 2FA is used by banks. The concept of one time password has not been understood by and large. One Time Password system as a second factor authentication increases the transaction safety for netizens. There are different variations of 2FA currently available in the market. The form factor varies from hard tokens to soft tokens. The soft token deployment is aimed at cell phones, laptops and ipads which is a common gadget available with an average citizen. There are other benefits like the ease of deployment and management. The Soft 2FA tokens also reduces the cost to consumer.
The program was over by around 2PM
I had an opportunity to address the gathering on the need for 2 factor authentication in bank transactions. Predominantly twin passphrase 2FA is used by banks. The concept of one time password has not been understood by and large. One Time Password system as a second factor authentication increases the transaction safety for netizens. There are different variations of 2FA currently available in the market. The form factor varies from hard tokens to soft tokens. The soft token deployment is aimed at cell phones, laptops and ipads which is a common gadget available with an average citizen. There are other benefits like the ease of deployment and management. The Soft 2FA tokens also reduces the cost to consumer.
The program was over by around 2PM
Labels:
Security,
Technology
Subscribe to:
Posts (Atom)
















