Despite popular assumptions that security risks increase as a person's online activity becomes shadier, findings from Cisco's 2013 Annual Security Report (ASR) reveal that the highest concentration of online security threats do not target pornography, pharmaceutical or gambling sites as much as they do legitimate destinations visited by mass audiences, such as major search engines, retail sites and social media outlets. In fact, Cisco found that online shopping sites are 21 times as likely, and search engines are 27 times as likely, to deliver malicious content than a counterfeit software site. Viewing online advertisements? Advertisements are 182 as times likely to deliver malicious content than pornography.
Do active risk analysis to know what attackers may strike at, and how
Gathering Intelligence about cyber attackers and hackers is difficult at best even for well-funded institutions, so it is unlikely that your organisation can or will want to achieve the true level of cyber intelligence about what is out and about in the cyber-attack world. It is much more effective and less daunting to focus on the intelligence gathering that you do control within your organisation. You need to have complete knowledge of your own systems, networks and organisation.
Normal cyber defense generally means your IT department trying to figure out what attackers are able to do with your system - how they can break in and what vulnerabilities can be exploited.
Fluid (EM Ltd writes:
We believe that IT departments can learn from traditional engineering techniques which work on a more proactive basis. The Mantra at Fluid is No Single Point of Failure, whether that is Cyber security or Infrastructure architecture.
An example from author Michael Davis is “Mechanical engineers are taught to approach problems using failure analysis. This technique involves identifying the conditions where a failure can occur instead of trying to figure out what failures can occur.
"Think of an explosion caused by an oily rag. Without oxygen, oil, the rag and the fire that ignites everything, an explosion won’t happen. Yet most security engineers trying to keep their networks from being blown wide open look for flames via log data (the attack) rather than finding the Oxygen,
oily rags and sparks — which must be present for an explosion or cyber-attack.”
Therefore your intelligence needs to be able to focus on looking for and identifying the hazardous conditions, each condition will have a subset of conditions and so forth until you will reach a condition that is addressable.
Instead of attempting to detect or prevent a zero-day exploit (an attack that exploits a previously unknown vulnerability in a computer application) from installing worms, virus, or Trojans on one of your machines you need to ensure that the conditions for an attack are eliminated.
Get rid of easily guessed passwords, weak administrative permissions on files and folders. These are all under your control, instead of trying to figure out where and how any malware, which you don’t control, might strike. Taking this approach means that your IT security team will know how the hackers do their mischief once they have got your machine!
You need to spend some time understanding and learning how an exploit works. It’s all about Penetration Testing, and how underlying exploits work. This isn’t easy, but it’s why here at www.fluidict.co.uk our consultants have spent years being trained about potential conditions.
In the meantime here’s how we suggest that can start to go about it:
1 Begin with an architectural diagram of your IT infrastructure and pick a point be it your server, workstation, database etc. and mark that machine as infected.
2 List how the attackers could go from that point to other points in your diagram. Can they break a password that is hidden on that device? Can they scan to find any vulnerability? Are the attackers able to take control of an authentication token, and authenticating to other devices? Can
they evade your log detection processes or incident responses
3 Clean each area and repeat the process until you have accessed every major asset type your organisation has, external, internal don’t forget remote sites, mobile workers or cloud services. So that you have then created offensive situations that list all the conditions required for an attack to happen, instead of just trying to figure out how an attack can happen.
4 Don’t forget Social Media Passwords and protocol when on line. Ensure all staff are suspicious of Direct Messages from contacts that seem out of character.
Start building the security team of the future.
Very often you or your IT team is not trained and experienced in proactive security. And for many organisations the cost of that type of talent is just not justified, therefore wherever you are in your IT
security it is good practice to start building relationships with reputable external IT companies who can prevent and can cure if necessary.
Organisations today face real advanced malware threats, and they can realize that today’s universities, and training programs don’t always teach the skills required to move to this proactive approach. Even some advanced security teams can’t tell whether a piece of malware is just
trying to direct you to a dodgy site to make fast cash or is into the long game of burrowing in to steal all your confidential data.
Companies can be reluctant to invest the time and money into training or recruiting this specialist type of employee. It’s best to call on the experts to ensure your systems are as safe as they can be. Fluid employs a “No Single Point of Failure” approach and can assess your requirements on an individual basis.
*******
Any Questions call 01954 700010 or email us [email protected] for free assessment today.
___________________________________________