Monday, 24 October 2016

Average cost of 'one' breached PHI data hard-drive !!


In the recent past, hackers used common devices such as webcams, baby monitors, video recorders etc. infected with software known as Mirai to attack websites of giant institutions like Twitter, Paypal, Netflix etc.  Even the websites with massive infrastructure powered by Dyn could not escape threat of DDoS to its Domain Name System. Users could not reach to many websites, including CNN, Wall Street Journal, Amazon.com etc. TOI reported on 23rd October.

Can anyone guess the impact of breached data on monetary terms, i.e. the average cost of ONE breached PHI (Protected Health Information) hard drive?

Although the cost of breached data cannot be estimated, an article on the basis of Ponemon study, sponsored by IBM, cost of one breached record is to the tune of 220 USD.  There are about 29000 records in a hard disk. The cost – 7 million Dollar!

EMC Global Data Protection Index shows that the average cost of INDUSTRY DATA LOSS in 2015 was to the tune of 9,14,000 Dollar for 2.36 Terabytes.

According to financial filings (March 3, 2016, HIPAA Journal), it is reported that Excellus BlueCross BlueShield data breach has reached to the tune of 17.3 million Dollar.

Monday, 17 October 2016

Cyber Security Review : 2016

Cybersecurity incites a level of fear that seems appropriate, given all that's at stake. These are boom times for cyberthreats, cyberattacks and cybercrime. More and more sophisticated attacks are being lauched. Every minute, the world sees about half a million attack attempts. This doesn't mean striving for perfection, but rather, ensuring that the most critical assets and information be secured and maximum possible risks be remediated and bringing down the residual risks to minimal acceptable levels.

In this post, we shall run through the cyber security stats for the year 2016 to help you get an insight of the attack trends :


10% - of the compromises were due to Malicious File upload vulnerability whereas 7% were due to Malicious insiders.

23% - of the total compromises have been targeted towards organizations from the retail industry.

40% - increase in compromises affecting corporate and internal networks in 2015.

31% - of the attacks, the attackers were targetting the Card Track data.

29% - of the attacks, the attackers targetting Card data from E-commerce transactions.

47% - of the attacks through POS malware were observed in the North American region.

79% - of the attacks were self-detected by the Latin Americans. However, 59% of the customer's attacks were detected by Law enforcement and Regulatory bodies.

168 - days are required on an average to detect an intrusion and were contained in approximately 15 days.

28 - days were needed on an average to contain an external intrusion after detection.

The more the number of days an attacker is within the network, the more damange he would perform and more time would be taken to recover from the damage caused.




Wednesday, 21 September 2016

IOT Security : Trend Analysis

Here, we come up with a most interesting summary of a highly trending topic in Cyber Security - "IOT Security". All devices and networks connected to the Internet form the gamut of IOT. Gartner estimates a 43% increase in IoT devices coming online in 2016. Since, the idea of networking appliances and other objects is relatively new, security was not considered as part of the product design.

Let's take a look at the security issues trending in the IOT space observed in the span of last 6 months.

1) New protocols (Eg. NTP) are used for DDOS (Never knew Time would be used to perform a DDOS attack?)

2) China, Russia, Ukraine, Brazil, and India are the top 5 sources of origin who perform these DDOS attacks.


3) China leads telnet bruteforce scans hunting for IoT devices with default passwords configured.

4) China, followed by Russia, Romania, Brazil, and Vietnam are the most likely locations for Command and Control (C&C) servers.

5) Around 2,174,216 telnet bruteforce scans were observed in last 6 months sourcing from 5,43,819 IP addresses.

6) Telnet scans have increased 140% year over year from July 2015

7) 50% of Telnet attacks were generated from top 13 ASNs

8) Around  6,293,889 SSH bruteforce attacks were observed in last 6 months from 28,616 IP addresses.

9) 92 ASNs comprise 2.1+ million Telnet brute force scans of which four of them are China telecom which comprise of 57% of the total Telnet scan.

10) The top 24 attacking ASNs (contribute >1% individually) combine for a total of 67% of the total attacks.

11) IOT Botnets using more than 52,000 IP addresses were DDOSing from multiple sources port (like port 53, 20000-60000) to fixed common destination port tcp 80.

12) SYN flood on port 80 is also performed with around 2.3 Gbps traffic.

13) 70% of the attacks are not originating from a spoofed source IP address.

14) The attack strategy used is as follows :
    a) Scan for IOT devices which have telnet enabled.
    b) After successful authentication via a bruteforce attack, attacker tries to identify the host's architecture and download the appropriate pack from the CnC server.
    c) Attempts to kill other additional rootkits already present or malware present on the compromised host.
    d) Connects to CNC using commonly used IRC channel.

The blessing and curse of IoT devices is that they are stateless devices which gets reboot under stress. This means their ability to launch attacks is very limited, but once re-infected and they can be leveraged all over again. So the next question to ponder upon is - How many IOT devices have their management ports available online and configured with vendor default passwords ?

All credits to :- F5 LABS THREAT ANALYSIS REPORT

Thursday, 8 September 2016

A botnet with IOT devices discovered !!

Soon after the public disclosure of the Shellshock bug, researchers had detected BASHLITE malware. This BASHLITE malware includes code from Shellshock exploit and it was used in the wild to run DDOS attacks. It had the ability to infect multiple Linux architectures, hence, attackers used it to target IoT devices.

Recently, researchers from Sucuri discovered a botnet composed of millions of CCTV devices used to launch DDoS attacks against websites. It was observed that the BASHLITE source code leaked in 2015 was used by malware developers to create their own variant.

This botnet includes :
95% - Digital Video Recorders (DVRs) or cameras
4%  - Routers
1%  - Linux servers

This helps to conclude that the composition of attacks through IoT devices has drastically increased compared to DDoS through compromised servers and home-based routers. A large percentage were found to be located in Taiwan, Brazil and Colombia. Bots were using white-labeled DVRs described as “H.264 DVRs” manufactured by Dahua Technology.

Wednesday, 7 September 2016

When you paid your ransom and lost your data too !!

According to a new study from Trend Micro, they observed that 1 out of 5 UK firms end up paying ransom and never get their data back too.

Some stats from the study in UK are :

20%   - companies reported ransom of £1000
24 hrs - deadline given to pay the ransom
26%   - believed that the data encrypted wasn't valuable.
33 hrs - spent on a average to fix the problem
37%   - companies worried about being fined if data were lost, so paid up ransom to get the data back or prevent disclosure.
44%  - UK firms have been infected with ransomware atleast once in last 2 years.
£540  - Average amount of rans
om requested
66%  - refused to pay and don't bargain too
60%  - companies were able to retrieve data from backup files
79     - new ransomware families found in 2016
300   - IT managers were polled for the study