Detecting Deep Fakes with a Heartbeat

Researchers can detect deep fakes because they don’t convincingly mimic human blood circulation in the face:

In particular, video of a person’s face contains subtle shifts in color that result from pulses in blood circulation. You might imagine that these changes would be too minute to detect merely from a video, but viewing videos that have been enhanced to exaggerate these color shifts will quickly disabuse you of that notion. This phenomenon forms the basis of a technique called photoplethysmography, or PPG for short, which can be used, for example, to monitor newborns without having to attach anything to a their very sensitive skin.

Deep fakes don’t lack such circulation-induced shifts in color, but they don’t recreate them with high fidelity. The researchers at SUNY and Intel found that “biological signals are not coherently preserved in different synthetic facial parts” and that “synthetic content does not contain frames with stable PPG.” Translation: Deep fakes can’t convincingly mimic how your pulse shows up in your face.

The inconsistencies in PPG signals found in deep fakes provided these researchers with the basis for a deep-learning system of their own, dubbed FakeCatcher, which can categorize videos of a person’s face as either real or fake with greater than 90 percent accuracy. And these same three researchers followed this study with another demonstrating that this approach can be applied not only to revealing that a video is fake, but also to show what software was used to create it.

Of course, this is an arms race. I expect deep fake programs to become good enough to fool FakeCatcher in a few months.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ransomware Victims That Pay Up Could Incur Steep Fines from Uncle Sam

Companies victimized by ransomware and firms that facilitate negotiations with ransomware extortionists could face steep fines from the U.S. federal government if the crooks who profit from the attack are already under economic sanctions, the Treasury Department warned today.

Image: Shutterstock

In its advisory (PDF), the Treasury’s Office of Foreign Assets Control (OFAC) said “companies that facilitate ransomware payments to cyber actors on behalf of victims, including financial institutions, cyber insurance firms, and companies involved in digital forensics and incident response, not only encourage future ransomware payment demands but also may risk violating OFAC regulations.”

As financial losses from cybercrime activity and ransomware attacks in particular have skyrocketed in recent years, the Treasury Department has imposed economic sanctions on several cybercriminals and cybercrime groups, effectively freezing all property and interests of these persons (subject to U.S. jurisdiction) and making it a crime to transact with them.

A number of those sanctioned have been closely tied with ransomware and malware attacks, including the North Korean Lazarus Group; two Iranians thought to be tied to the SamSam ransomware attacks; Evgeniy Bogachev, the developer of Cryptolocker; and Evil Corp, a Russian cybercriminal syndicate that has used malware to extract more than $100 million from victim businesses.

Those that run afoul of OFAC sanctions without a special dispensation or “license” from Treasury can face several legal repercussions, including fines of up to $20 million.

The Federal Bureau of Investigation (FBI) and other law enforcement agencies have tried to discourage businesses hit by ransomware from paying their extortionists, noting that doing so only helps bankroll further attacks.

But in practice, a fair number of victims find paying up is the fastest way to resume business as usual. In addition, insurance providers often help facilitate the payments because the amount demanded ends up being less than what the insurer might have to pay to cover the cost of the affected business being sidelined for days or weeks at a time.

While it may seem unlikely that companies victimized by ransomware might somehow be able to know whether their extortionists are currently being sanctioned by the U.S. government, they still can be fined either way, said Ginger Faulk, a partner in the Washington, D.C. office of the law firm Eversheds Sutherland.

Faulk said OFAC may impose civil penalties for sanctions violations based on “strict liability,” meaning that a person subject to U.S. jurisdiction may be held civilly liable even if it did not know or have reason to know it was engaging in a transaction with a person that is prohibited under sanctions laws and regulations administered by OFAC.

“In other words, in order to be held liable as a civil (administrative) matter (as opposed to criminal), no mens rea or even ‘reason to know’ that the person is sanctioned is necessary under OFAC regulations,” Faulk said.

But Fabian Wosar, chief technology officer at computer security firm Emsisoft, said Treasury’s policies here are nothing new, and that they mainly constitute a warning for individual victim firms who may not already be working with law enforcement and/or third-party security firms.

Wosar said companies that help ransomware victims negotiate lower payments and facilitate the financial exchange are already aware of the legal risks from OFAC violations, and will generally refuse clients who get hit by certain ransomware strains.

“In my experience, OFAC and cyber insurance with their contracted negotiators are in constant communication,” he said. “There are often even clearing processes in place to ascertain the risk of certain payments violating OFAC.”

Along those lines, OFAC said the degree of a person/company’s awareness of the conduct at issue is a factor the agency may consider in assessing civil penalties. OFAC said it would consider “a company’s self-initiated, timely, and complete report of a ransomware attack to law enforcement to be a significant mitigating factor in determining an appropriate enforcement outcome if the situation is later determined to have a sanctions nexus.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Critical Vulnerabilities Found in Remote Access Software

Critical Vulnerabilities Found in Remote Access Software

Researchers at an Israeli operational technology (OT) company have discovered multiple critical vulnerabilities in two popular industrial remote access software solutions.

The flaws can be exploited to access industrial production floors, break into company networks, tamper with data, or steal highly sensitive trade secrets. 

Researchers at Otorio discovered the vulnerabilities in remote access systems made by Austrian automation and process control technology company B&R Automation and in mbConnect24 software made by German company mbConnect Line

Otorio, which is headquartered in Tel Aviv, delivers next-generation secured OT, IOT, industrial control systems (ICS) security, and digital risk management solutions.

Six critical flaws affecting B&R Automation were identified in the company’s SiteManager and GateManager software that form part of the company’s Secure Remote Maintenance Suite.  mbConnect’s mbConnect24 is used mostly for remote connection to industrial assets.

Describing the importance of the systems in which the flaws were spotted, Otorio stated: “These systems allow operations professionals access to manage, service and maintain industry machines remotely from anywhere in the world. Together, they serve thousands of sites in industries such as automotive, energy, oil & gas, metal, packaging, maritime and more.”

Otorio announced the flaws earlier today. Details of the vulnerabilities are now available on the US Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency’s website.

Researchers noted that by exploiting the B&R flaws, an attacker who has gained authorized access to the B&R solution (for example, by simply acquiring a legitimate general license, available to anyone) can view sensitive information about other users whose information resides on the same server. 

This information, which may include data regarding assets, processes, and other sensitive items, could be used by attackers to target other organizations and their industrial systems.

Worryingly, exploitation of the flaws could also cause all operations to cease. Otorio stated: “The attacker can also trigger a repeated restart of both the GateManager and the SiteManager, leading eventually to a loss of availability and halt production.”

The vulnerabilities found in a highly accessible zone of mbConnect24 have since been fixed by the company in newer versions of the product. They allowed an attacker to leverage a vulnerable, outdated library to upload crafted authentication files.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

New Toolkit Secures US Teleworkers

New Toolkit Secures US Teleworkers

The Cyber Readiness Institute (CRI) has expanded its partnership with the US Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) to improve the cybersecurity of remote workers.

CISA and the CRI have together launched a new cybersecurity toolkit specifically focused on helping companies protect themselves, their customers, and their employees as millions have made the switch to telecommuting.

Since June, elements of CRI’s Cyber Readiness Program have been incorporated into CISA’s Cyber Essential Toolkits. Now, CISA will be offering a new Telework Essentials Toolkit boosted by significant contributions from the Institute.

The Telework Essentials Toolkit contains three personalized modules of role-appropriate security considerations for executive leaders, IT professionals, and teleworkers themselves. Executive leaders are provided with actions that can drive cybersecurity strategy, investment, and culture, while IT professionals are given a strategy to develop security awareness and vigilance.

Teleworkers are provided with guidance on how to develop their home network security awareness and be on the alert for threats.

In addition, CISA has created a dedicated resource offering telework cybersecurity guidance, including the new Telework Essentials Toolkit. Users can access helpful guidance on video conferencing, wireless technology, and using VPNs, as well as general remote working advice.

To support the many business that have restructured their operations to support people working remotely due to the COVID-19 pandemic, CRI has produced a series of guides that help managers and employees address the cyber-challenges of remote work environments. 

The guides also contain useful information that can be applied to hybrid environments in which some employees will continue to work remotely while others come back to the office. 

“Covid-19 forced our nation’s SMEs to transform overnight,” said Kiersten Todt, managing director of CRI. 

“Telework has created new challenges for employees, IT staff and business leaders. We appreciate the opportunity to contribute to CISA’s Telework Essentials Toolkit by providing easy-to-implement actions, featured in CRI’s resources, that will be enable businesses to continue to thrive in this new environment.”

In response to the plague of ransomware that has been claiming victims around the world, CRI has also developed a ransomware guide for SMEs that CISA has distributed to its stakeholders.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk