Showing posts with label cyber security. Show all posts
Showing posts with label cyber security. Show all posts

Friday, August 10, 2012

With Gauss tool, cyberspying moves beyond Stuxnet, Flame


kaspersky5
There is enough evidence that this is closely related to Flame and Stuxnet, which are nation-state sponsored attacks. We have evidence that Gauss was created by the same "factory" (or factories) that produced Stuxnet, Duqu and Flame.


CNET - Kaspersky Lab finds Gauss, a spying malware that collects financial information and resembles Flame. Components are named after famous mathematicians.

Gauss, a new "cyber-espionage toolkit," has emerged in the Middle East and is capable of stealing sensitive data such as browser passwords, online banking accounts, cookies, and system configurations, according to Kaspersky Lab. Gauss appears to have come from the same nation-state factories that produced Stuxnet.

According to Kaspersky, Gauss has unique characteristics relative to other malware. Kaspersky said it found Gauss following the discovery of Flame. The International Telecommunications Union has started an effort to identify emerging cyberthreats and mitigate them before they spread.

In a nutshell, Gauss launched around September 2011 and was discovered in June. Gauss, which resembles Flame, had its command and control infrastructure shut down in July, but the malware is dormant waiting for servers to become active. Kaspersky noted in an FAQ:

Among Gauss' key features:
  • Gauss collects data on machines and sends it to attackers. This data includes network interface information, computer drive details and BIOS characteristics.
  • The malware can infect USB thumb drives using the vulnerabilities found in Stuxnet and Flame.
  • Gauss can disinfect drives under certain circumstances and then uses removable media to store collected data in a hidden file.
  • The malware also installs a special font called Palida Narrow.
More

Sunday, March 4, 2012

FBI Chief Calls Cyberthreats Public Enemy No. 1




Cyberattacks in various forms — cybercrime, terrorist acts committed via computers and cybattacks from foreign states — will soon be the United States’ most serious threat, according to FBI Director Robert Mueller. He urged the private sector to help by sharing information with law enforcement. His remarks were made at the RSA Conference in San Francisco.

In the near future, cyberthreats will be the leading threat to the United States, FBI Director Robert Mueller warned in a speech on Thursday at the RSA Conference in San Francisco.
Traditional crime, from mortgage and healthcare fraud to child exploitation, have moved online, while terrorists have become increasingly cyber-savvy, Mueller said.

Meanwhile, law enforcement is also confronting hacktivists, organized crime, hostile foreign nations spying on the U.S. and online and mercenary hackers.

Law enforcement needs to take lessons learned from fighting terrorism and apply them to cybercrime, he stated.

While the FBI has built up substantial expertise to deal with cyberthreats, it needs help from the private sector, Mueller said, repeating his often-made call for companies to be forthright about reporting data breaches.

“With cyberterrorism, there are fewer high-impact targets that likely have sophisticated defenses,” Tim Keanini, chief technology officer at nCircle, told TechNewsWorld. “Cybercrime, on the other hand, has become an actual business model with countless targets.”

Cybercrime “has had magnitudes more bite than cyberterrorism for a long time now,” mused Randy Abrams, an independent security consultant.

The Rise of the Terrorist in Cyberspace

Terrorist organizations are using the Internet to grow and connect with each other, and they are doing so openly, Mueller said.           More

Friday, July 15, 2011

Critics: U.S. cybersecurity plan has holes, few new items

IDG News Service - The new Strategy for Operating in Cyberspace issued by the Department of Defense on Thursday covers a collection of topics that have been discussed for years and leaves a number of important unanswered questions, critics said.

Deputy Secretary of Defense William Lynn unveiled the new strategy during a speech on Thursday, and a transcript of the speech was made available online.

"Our strategy's overriding emphasis is on denying the benefit of an attack. Rather than rely on the threat of retaliation alone to deter attacks in cyberspace, we aim to change our adversaries' incentives in a more fundamental way. If an attack will not have its intended effect, those who wish us harm will have less reason to target us through cyberspace in the first place," Lynn said.

The plan contains a handful of initiatives, including treating cyberspace as a domain like land and sea; introducing new network defenses that include sensors, software and signatures to detect and stop malicious code; coordinating with the Department of Homeland Security and the private sector; and working with other countries.      More

Sunday, July 10, 2011

A Separate Internet Could Curb Cyber Threats, Former CIA Chief Says

 

















The Yeshiva World - To combat cyberattacks, the U.S. may need more than new cyberdefenses. It might need a whole new piece of Internet infrastructure.

So says former CIA director Michael Hayden, who served under President G.W. Bush, and he’s not the only one. Several lawmakers and the current Cyber Command chief Gen. Keith Alexander are toying with the notion of creating a “.secure” domain where Fourth Amendment rights to privacy are voluntarily foregone in order to keep that corner of the Internet free of cyber criminals.

The idea goes something like this: China and other regimes around the world inherently have an upper hand when it comes to cyber defense because their lack of civil liberty protections lets the government freely monitor online activity. Things like “deep packet inspection” (which gained notoriety during Iranian election protests back in 2009) that let governments monitor citizens traffic also let them monitor for unusual activity.

That activity could be cyber criminals at work, or it could be foreign-backed cyber warriors and cyber spies working to weaken a nation’s infrastructure or penetrate sensitive government systems. Regardless, other countries are better protected.

The U.S. Internet, by virtue of its adherence civil liberties, is more like the wild west. Everyone does everything online anonymously, and while that’s great for liberties, it’s also dangerous when cyber criminals/foreign hackers are roaming the cyber countryside.     More

Thursday, June 30, 2011

Massive botnet 'indestructible,' - 4.5M-strong botnet 'most sophisticated threat today' to Windows PCs

Computerworld - A new and improved botnet that has infected more than four million PCs is "practically indestructible," security researchers say.

"TDL-4," the name for both the bot Trojan that infects machines and the ensuing collection of compromised computers, is "the most sophisticated threat today," said Kaspersky Labs researcher Sergey Golovanov in a detailed analysis Monday.

"[TDL-4] is practically indestructible," Golovanov said.
Others agree.

"I wouldn't say it's perfectly indestructible, but it is pretty much indestructible," said Joe Stewart, director of malware research at Dell SecureWorks and an internationally-known botnet expert, in an interview today. "It does a very good job of maintaining itself."

Golovanov and Stewart based their judgments on a variety of TDL-4's traits, all which make it an extremely tough character to detect, delete, suppress or eradicate.

For one thing, said Golovanov, TDL-4 infects the MBR, or master boot record, of the PC with a rootkit -- malware that hides by subverting the operating system. The master boot record is the first sector -- sector 0 -- of the hard drive, where code is stored to bootstrap the operating system after the computer's BIOS does its start-up checks.