Saturday, 12 November 2016

What every organization MUST-DO for Cybersecurity !!

Not a single day passes without reporting about cybersecurity breach in one way or other. Whether large or small companies, there is no escape from cyber attacks.

The scope, according to Norman Van, towards cyber security of an organization, is meant for confidentiality, availability and integrity of data. Information Systems are the sum total of data collections and associated persons, procedures, processes and software as well as the provision for the information system for storing, processing and communication.

Some of the basic threats –

We are listing below some of the important basic threats to be attended to in respect of cyber security. Every organization must pay attention to these basics to stay away from cyber security threats.

Ø  Secure Websites and web apps against attacks and malware infection.

Ø  End points are like open door, and hence, security measures must be implemented to safeguard user devices against virus, intrusion, browser etc.

Ø  Social networking has become apparently smart and complex, and hence, phishing attacks are very powerful and organized, and are to be prevented.

Ø  There are always loopholes or vulnerabilities in the software which are always aimed by attackers.  Hence, necessary patch works must be done to keep abreast of times.  A great majority of exploitation was on old software.

Ø  Data breaches involving employees is one of the common occurrences, hence it should be checked.

Ø  Implementation of effective password is absolutely necessary.  Refer our earlier blog where its flaws and remedies are suggested.

Ø  Vis-a-vis growth of smart devices, and cloud services, security threats of IOTs also increased significantly, hence, information security is very essential.

Ø  Encryption and DLP should be used to safeguard sensitive data, and restriction should be imposed on the use of unauthorized devices like USB, extra portable hard drives etc.

Ø  Once a website is attacked, critical information would be lost, hence back up system would be adopted.

Cybersecurity is not a onetime job.  It is a continuous process.  Due to advancement of technology, new techniques are tried every time by attackers to breach web information.

Wednesday, 2 November 2016

Icarus can hijack any popular Drones mid-flight !!


Now a person can hijack nearly any drone mid-air just by using a tiny gadget.

Mr. Jonathan Andersson, who is the manager and security researcher at Trend Micro’s TippingPoint DVLab division, demonstrated a small devise, which he has made, at the PacSec security conference in Tokyo, Japan on Wednesday last.

According to him, his device called Icarus can hijack any popular Drones mid-flight, allowing hackers to lock the owner out, and take complete control of the drones.

This tiny Icarus can also attack many radio-controlled devices like helicopters, cars, boats and other remote control gears that run over the most popular wireless transmission control protocol called DSMx. DSMx is a protocol used to facilitate communication between radio controllers and devices, including drones, helicopters, and cars etc.


Icarus works by taking effect of DSMx protocol which permits the hackers to take full control over targeted Drones that allows attackers to steer, accelerate, brake and even crash them.

What is the lacuna that permits the hackers? Andersson explained that the DSMx protocol does not encrypt the ‘secret’ key that pairs a controller and hobbyist device, which facilitate an attacker to extract this secret by launching several brute-force attacks.  So, once the drone hijacker (Icarus) grabs the secret key, an attacker can send malicious commands to restrict the original owner of the drone from sending legitimate control commands, and instead, the drone will accept commands from the attacker.

Despite providing some patches and updated hardware, manufacturers have not been fully equipped with to provide a robust solution against such threats.

Chinese hackers won prize money of $215,000 !!


In the contest run by Trend Micro's Zero Day Initiative, Tokyo, Japan, for hacking Mobile Pwn2Own, Tencent Keen Security Lab Team from China has won a total prize money of $215,000. 

High security measures were put into effect to devices for both Google's Nexus 6P phones and Apple's iPhone 6S, but still they fell victim to the Chinese hackers.

Google's Nexus 6P: For hacking the Nexus 6P, the Keen Lab Team used a combination of two vulnerabilities and other weaknesses in Android and managed to install a rogue application on the Google Nexus 6P phone without user interaction.

Apple's iPhone 6S: The hackers took advantage of two iOS vulnerabilities -  a use-after-free bug in the renderer and a memory corruption flaw in the sandbox – and stole pictures from the device.  Even though Apple has implemented iOS update, hackers could break the securities successfully.  They have recently credited to have found a threat of remote code execution error.  They have also informed that an update of iOS 10.1 can also be hacked effortlessly.

Monday, 24 October 2016

Average cost of 'one' breached PHI data hard-drive !!


In the recent past, hackers used common devices such as webcams, baby monitors, video recorders etc. infected with software known as Mirai to attack websites of giant institutions like Twitter, Paypal, Netflix etc.  Even the websites with massive infrastructure powered by Dyn could not escape threat of DDoS to its Domain Name System. Users could not reach to many websites, including CNN, Wall Street Journal, Amazon.com etc. TOI reported on 23rd October.

Can anyone guess the impact of breached data on monetary terms, i.e. the average cost of ONE breached PHI (Protected Health Information) hard drive?

Although the cost of breached data cannot be estimated, an article on the basis of Ponemon study, sponsored by IBM, cost of one breached record is to the tune of 220 USD.  There are about 29000 records in a hard disk. The cost – 7 million Dollar!

EMC Global Data Protection Index shows that the average cost of INDUSTRY DATA LOSS in 2015 was to the tune of 9,14,000 Dollar for 2.36 Terabytes.

According to financial filings (March 3, 2016, HIPAA Journal), it is reported that Excellus BlueCross BlueShield data breach has reached to the tune of 17.3 million Dollar.

Monday, 17 October 2016

Cyber Security Review : 2016

Cybersecurity incites a level of fear that seems appropriate, given all that's at stake. These are boom times for cyberthreats, cyberattacks and cybercrime. More and more sophisticated attacks are being lauched. Every minute, the world sees about half a million attack attempts. This doesn't mean striving for perfection, but rather, ensuring that the most critical assets and information be secured and maximum possible risks be remediated and bringing down the residual risks to minimal acceptable levels.

In this post, we shall run through the cyber security stats for the year 2016 to help you get an insight of the attack trends :


10% - of the compromises were due to Malicious File upload vulnerability whereas 7% were due to Malicious insiders.

23% - of the total compromises have been targeted towards organizations from the retail industry.

40% - increase in compromises affecting corporate and internal networks in 2015.

31% - of the attacks, the attackers were targetting the Card Track data.

29% - of the attacks, the attackers targetting Card data from E-commerce transactions.

47% - of the attacks through POS malware were observed in the North American region.

79% - of the attacks were self-detected by the Latin Americans. However, 59% of the customer's attacks were detected by Law enforcement and Regulatory bodies.

168 - days are required on an average to detect an intrusion and were contained in approximately 15 days.

28 - days were needed on an average to contain an external intrusion after detection.

The more the number of days an attacker is within the network, the more damange he would perform and more time would be taken to recover from the damage caused.