Showing posts with label application attacks. Show all posts
Showing posts with label application attacks. Show all posts

Tuesday, September 10, 2013

The Malware Mess

A couple weeks ago McAfee Labs released the McAfee Threats Report: Second Quarter 2013, which found that Android-based malware marked a 35% growth rate not seen since early 2012.  They also found twice as many new ransomware offerings in Q2 as in Q1, bringing the 2013 ransomware count higher than the total found in all previous periods combined.  Everything was in play - SMS stealing bank malware, infected legitimate apps, malicious apps in sheep's clothing, along with fake dating and entertainments apps.  A lot of areas that we spend a good portion of our mobile time.

In addition to mobile threats, Q2 also saw a 16% uptick in suspicious URLs and a 50% increase in digitally-signed malware samples.  Attackers are showing that they can adapt to the criminal opportunities and continue to infiltrate the ever changing infrastructure.  Ransomware, a very popular and profitable scheme, where pop-ups or other messages threaten the user unless they pay a ransom, doubled from Q1 to Q2.  Hey, if it works, might as well.  Malware signed with legitimate certificates increased 50% to 1.2 million samples.  You think you're getting the safe code due to the certificate's authentication but that cozy blanket gets cold quick.  Malware also continues to find life with infected URLs according to McAfee.  The total number of suspect URLs found reached 74.7 million or a 16% increase over Q1.  The Indexed Web is at least 3.82 billion pages so around 2% of the web but still.  I might suggest, 'watch what you type, don't click suspicious links, avoid porn sites,' and other rather obvious actions but these days it could be delivered through an ad loading on a popular news site.  Almost no one is immune.  SPAM continues to hog email servers accounting for almost 70% of all global email volume.  That's nuts.  Think about it all the legitimate email we send over a month and it only accounts for 30% of all email?!?  What a waste of resources.  Other highlights included cyber espionage campaigns and attacks on digital currency.

These threats come at a time where there seems to be a disconnect between executives and their technical teams. 

The Ponemon Institute's most recent research shows that when it comes to locking down enterprise infrastructure, the application layer is responsible for more than 90% of all security vulnerabilities, yet more than 80% of IT security spending continues to be at the network and endpoint layer.  According to Ponemon, 'Most Organizations are Woefully Behind in Application Security.'  For it's 'Current State of Application Security Report' , they asked 642 IT professionals (both executive & engineering) 20 questions concerning tools usage, development team knowledge and security best practices to better understand the maturity of an organization’s application security program in comparison to the core competencies of high-performing organizations.  They found that a much higher percentage of executive-level respondents believe their organizations are following security procedures through the lifecycle of application development than do the engineers who are closest to executing the security processes.  For instance, 71% of executives interviewed believe that application security training is available and up to date but only 20% of technical staff felt the same.  Around 67% of execs feel they have a mature application security program, compared to 33% of technical staff and 75% of executives believe that a secure architecture exists in their organization verses 23% of technical staff.  Someone is either not communicating or many organizations do not yet consider the need to proactively do something about application security or even attempt to understand application security risks.

What is troublesome is that even with all the media attention and the afore mentioned malware stats, most organizations are not building nor testing their applications for security. According to the Ponemon report, only 43% of respondents say they have a process in place to test for vulnerabilities prior to release, and only 41% are using automated scanning tools to test applications during development. And just to pile on, only 42% push their applications to manual penetration testing by internal teams or from a third party. 

So, threats are increasing (I feel like I say this multiple times a year) and it seems that organizations' response to them are decreasing...or at least not taking them seriously enough.  In many ways, it is kinda like the real world.  We think, feel, believe that we're safe until something happens...then we take all the precautions.  Many organizations need to do that yesterday. 

Today's technologies are awesome but every once in a while I do miss 4 TV stations (including PBS), typewriters, rotary phones, mimeograph machines, S&H Green Stamps and the hard wires of yesteryear.

ps

Related:

 

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, June 11, 2013

Small Business is a Big Target

If you think that small businesses are not an enticing enough target to breach, think again.  While the media has certainly upped it's coverage over the last couple years pertaining to data loss, many of the headlines involved global brands and tens of thousands records...not the corner deli, the mom/pop shop or the new start up.  Yet a couple of recent reports show that small businesses and start-ups are prime targets for data loss.

The annual, chuck full of stats, Verizon Data Breach Report noted that of the 621 confirmed data breaches, almost half happened at companies with less than 1000 employees and almost 200 at companies with less than 100 employees.  A Symantec report echoed the finding.  In theirs, small businesses with less than 250 employees accounted for 31% of the attacks in 2012, up 18% from 2011.  Symantec also notes that start-ups are especially vulnerable in the early going.

Why are these groups targets?

They have valuable data - intellectual property, financial information, digital identities - but may not have the resources to properly protect that data.  Many large, global companies have beefed up their security in fear of becoming the next headline in a major newspaper.  Thieves usually go after the easiest target - those with limited resources to protect against such an attack.  Thieves may also infiltrate a smaller organization to jump on a global network if a partnership is in place. Take out the villages before entering the capital.  In a start-up's situation, as they quickly launch, employees may be enticed to click a malicious link in an email...which then spreads.  Most startups get infected with malware within the first year.

From marketing organizations to cleaning products to credit repair services, here are some stories of how cyber attacks almost destroyed 5 small businesses.

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Thursday, February 21, 2013

Inside Look: BIG-IP ASM Botnet and Web Scraping Protection

I hang with WW Security architect Corey Marshall to get an inside look at the Botnet detection and Web scraping protection in BIG-IP ASM.

 

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1]  o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Friday, June 29, 2012

In 5 Minutes or Less Video - IP Intelligence Service

I show you how to configure the IP Intelligence Service available on BIG-IP v11.2, in 5 Minutes or Less.  By identifying relevant IP addresses and leveraging intelligence from cloud-context security solutions, F5's new IP Intelligence service combines valuable information on the latest threats with the unified policy enforcement capabilities of the BIG-IP application delivery platform.   Deployed as part of the BIG-IP system, F5’s IP Intelligence service leverages data from multiple sources to effectively gather real-time IP threat information and block connections with those addresses. The service reveals both inbound and outbound communication with malicious IP addresses to enable granular threat reporting and automated blocking, helping IT teams create more effective security policies to protect their infrastructures.

In 5 Minutes or Less - IP Intelligence Service

A free 30 day evaluation of the IP intelligence service is available.

ps

Related:

Technorati Tags: F5,big-ip,security,threat prevention,infrastructure,big data,cloud,GDI,ip intelligence

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Monday, June 18, 2012

The Exec-Disconnect on IT Security

Different Chiefs give Different Security Stories.

A recent survey shows that there is a wide gap between CEOs and Chief Security Officers when it comes to the origin and seriousness of security threats.  They differ on how they view threats to IT Infrastructure  and remain far apart on how to best address an issue that according to analyst reports, costs organizations more than $30 billion annually.  The survey of 100 CEOs and 100 CISO (or other C-levels with security responsibility), shows that the discrepancy is often due to lack of communication.  36% of CEOs said that they never get a security report from their CISO and only 27% receive updates on a regular basis.  Is it the CISO that doesn’t report back or the CEO that is not interested?  Let’s look at some more data.

The CISO felt that the biggest threat was from internal (their employees) due to lack of education and attention while the CEO felt that the biggest threat was from the outside, such as phishing attacks.   Thus, 61% of CEOs said they did have enough time and resources to adequately train the staff on how to mitigate threats while Only 27% of CISOs felt the same.  It’s opposite day.  When asked if their IT systems were ‘definitely’ or ‘probably’ under attack without their knowledge, 58% of CISOs said yes while only 26% of CEOs agreeing.  The chasm grows.  What percentage of each, do you think, said they were very concerned about their IT systems getting hacked?  30 seconds on the clock, please.  Don’t peek.  Only 15% of CEOs and ‘only’ 62% of CISOs are anxious about breaches.  15%?  That’s it?  Maybe they have great confidence in their security team…or, they don’t have the information.  65% of CEOs admitted to not having the sufficient data needed to interpret how security threats translate to overall business risk.  Wow, the very day-to-day operations.  Granted, the CEO is further removed from the specific threats and how they are handled but there is clearly a distance between how each views threats and the company’s ability to successfully mitigate them.

Lack of interest or lack of understanding/information?  Probably both.  An old adage was that a great boss hired people who were good at the things he/she wasn’t so good at.  Surround yourself with those who know their areas better.  Or maybe there is a culture that you don’t alert the top unless it’s dire, critical or unstoppable.   Communication or interest, it is evident that the C-suite isn’t really talking about these critical business issues especially when 3 times as many CEOs worried about losing their jobs following an attack than did CISOs.

ps

References

Technorati Tags: F5, security research, botnet, threat landscape, Pete Silva, security, business, technology, cloud,compliance,regulations, web,internet

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Monday, June 11, 2012

The Changing Security Threat Landscape Infographic

In conjunction with a new video and a security white paper, this F5 infographic validates the need for organizations to rethink security practices.  The global security threat landscape is rapidly evolving and has changed dramatically in ways unfathomable just a few years ago.  Due to this growing complexity and the rise of many unknown forces in the battle for information and causes, customers must rethink how they protect their network, applications, and data from ever-changing threats.

 

F5_Security-Infograph_RevG-1024_060812

(you can reuse within your own blogs, etc)

ps

Resources:

Technorati Tags: F5, security research, botnet, threat landscape, Pete Silva, security, business, technology, cloud, compliance,regulations, web,internet

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]