Holy Grail of Security: Answers to ‘Did XYZ Work?’ – Podcast

Verizon DBIR is already funny, useful & well-written, and it just got better with mapping to MITRE ATT&CK TTPs. The marriage could finally bring answers to “What are we doing right?” instead of the constant reminders of what’s not working in fending off threats.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Remote Browser Isolation: The Next Great Security Technology is Finally Attainable

Security professionals and technologists old enough to remember renting movies at Blockbuster on Friday nights likely also remember a time when the internet was a new phenomenon full of wonder and promise.  These same individuals probably view it through a more skeptical lens seeing it now as a cesspool of malware and great risk.  It’s also widely understood that no web security solution can offer perfect protection against the metaphorical minefield that is the internet.  This last statement, however, is being challenged by a new technology that is grasping at the title of perfect web security.  This mythical technology is Remote Browser Isolation, or RBI, and it can be argued that it does, in fact, provide its users with invincibility against web-based threats.

Remote Browser Isolation changes the playbook on web security in one very fundamental way: it doesn’t rely on detecting threats.  When a user tries to browse to a website, the RBI solution instantiates an ephemeral browser in a remote datacenter which loads all the requested content.  The RBI solution then renders the website into a dynamic visual stream that enables the user to see and safely interact with it.

Figure 1: How Remote Browser Isolation works.

User behavior can be controlled at a granular level, preventing uploads, downloads, and even copy & paste using the local clipboard.  When properly configured, absolutely none of the content from the requested site is loaded on the local client.  For this reason, it can be argued that it’s literally impossible for malware to be delivered to the local client.  Of course, the RBI solution’s ephemeral browser instance may be compromised, but it will be fully isolated from the organization’s valuable assets and data, rendering the attack harmless.  As soon as the user closes their local browser tab, the ephemeral browser is destroyed.

The value of this cannot be overstated.  The world is increasingly conducting its affairs through web browsers, and the challenge of detecting threats continues to increase at an exponential rate.  While there is great efficacy and value in the threat intelligence and malware detection capabilities of web security solutions today, the “cat & mouse” game being played with cybercriminals means that they’re simply never going to offer perfect protection.  Attackers often use zero-day threats coupled with domains registered perhaps within the past few minutes to compromise their victims, and these methods will too often succeed in circumventing any detection-based security measures.  The game-changing efficacy of RBI and the fact its inception was actually more than 10 years ago should bring an obvious question to mind – If it’s so great, why doesn’t every organization in the world use RBI today?  There are a few relevant answers to this, but one rises above all the rest: cost.

RBI’s method of instantiating remote web browsers for all users precludes the possibility of any implementation that is not expensive to deliver.  Consider the size of a modern enterprise, the number of users, the number of web browser tabs an average user keeps open, and then consider the amount of memory and CPU consumed by each of those tabs.  To mirror these resources in a remote datacenter will always be a costly proposition.  For this reason, many RBI solutions on the market today may literally consume the entire security budget allocated for each licensed user.  As prevalent as web-based threats are today and as effective as RBI’s protection may be, no security organization can dedicate most or all of their security budget to a single technology or even a single threat vector.

To better understand the cost problem and how it may be solved, let’s take a closer look at the two most common use cases for RBI.  The first and most common use case is handling uncategorized sites or sites with unknown risk, known as selective isolation.  As mentioned before, attackers will often use a site that was registered very recently to deliver their web-based threats to victims.  Therefore, organizations often want to block any site that has not been categorized by their web security vendor.  However, the problem is that many legitimate sites can be uncategorized resulting in unnecessary blocking that may impact business.  Managing such a policy is very tedious, and the user experience tends to suffer greatly.  RBI is an ideal solution to this problem where you can grant users access to these sites while maintaining a high level of security.  This situation calls for a selective use of RBI where trusted sites are filtered through more traditional means while only the unknown or high-risk sites are isolated.

The other common need for RBI is various groups of high-risk users.  Consider C-level executives who have access to highly sensitive information relating to business strategies, intellectual property, and other information that must remain private.  Another common example is IT administrators who have elevated privileges that could be devastating if their accounts were compromised.  In these scenarios, organizations may look to isolate all of the traffic for these users including even sites that are trusted.  Typically, this full isolation approach is reserved for only a subset of users who pose a particularly high risk if compromised.

In light of these two use cases, selective isolation and full isolation, let’s take a closer look at the cost of this invincibility-granting technology.  Let’s consider a hypothetical organization, Brycin International, who has a total of 10,000 users.  Brycin has identified 400 users who either have access to critical data or have elevated permissions and therefore require full-time isolation.  We will assume a street price of $100 per user for full time isolation totaling $40,000 for these users.  This seems like a reasonable cost considering the elevated risk a compromise would represent for any one of these users.  Brycin would also like to leverage selective isolation for the rest of the user population, or 9,600 users.  Some solutions may require purchasing a full license, but most offer a discounted license for selective isolation.  We will assume a generous discount of 60%, resulting in a total cost of $40 per user or $384,000 for the rest of the organization.  This gives us a total price tag of $424,000 for Brycin, or an average cost of $42.40 per user.

Not only is this a steep cost for our 10,000-user enterprise, but the cost does not at all align with the value or the cost to deliver the solution.  The 9,600 selective isolation users may represent 96% of the user population, but when you consider the fact that only a small percentage of their web traffic will actually be isolated – state-of-the-art web threat security stacks can detect as much as 99% of all threats, leaving 1% of all traffic to be isolated – they generate perhaps less than 20% of the isolated web traffic.  The full isolation users, while a minority of the license count, will represent the bulk of the isolated web traffic – a little more than 80%.  However, despite the fact that selective isolation users are responsible for such a small share of all isolated traffic and given the generous 60% discounted licensing, they are still by far the largest expense at over 90% of the total solution cost!  This ratio of cost to value simply will not align with the budget and goals of most security organizations.

Figure 2: The disproportionate relationship between RBI users, traffic load, and solution cost.

McAfee Enterprise has now upended this unfortunate paradigm by incorporating remote browser isolation technology natively into our MVISION Unified Cloud Edge platform.  McAfee Enterprise offers two licensing options for RBI: RBI for Risky Web and Full Isolation.  RBI for Risky Web uses an algorithm built by McAfee Enterprise to automatically trigger browser isolation for any site McAfee Enterprise determines to be potentially malicious.  This is designed to address the most common use case, selective isolation, and it is included at no additional cost for any Unified Cloud Edge customer.  Additionally, Full Isolation licenses can be purchased as an add-on for any users that require isolation at all times.  These Full Isolation licenses allow you to create your own policy dictating which sites are isolated or not for these users.

Now, let’s revisit Brycin International’s cost to deliver enterprise-wide RBI if they chose McAfee Enterprise.  As we saw earlier, despite the fact the selective isolation users generated less than 20% of the traffic, they represented over 90% of the total cost of the solution.  With McAfee Enterprise’s licensing model, these users would not require any additional licenses at all, reducing this cost to zero!  Now, Brycin only has to consider the Full Isolation add-on licenses for their 400 high-risk users, or $40,000 – this is now the entire cost for the enterprise-wide RBI deployment.  While $100 per user still may exceed the per-user security budget for Brycin, it is now diluted by the total user population, reducing the per-user cost of the RBI deployment from $42.40 to only $4.  This is a tremendous reduction in cost for equal or greater value, making RBI much more likely to fit into Brycin’s budget and overall security plans.

This may beg the question, “How can McAfee Enterprise do this?”  In short, as one of the most mature security vendors in the world, McAfee Enterprise has the most powerful threat intelligence and anti-malware capabilities in the market today.  McAfee Enterprise’s Global Threat Intelligence service leverages over 1 billion threat sensors around the world reducing the unknowns to an extremely small fraction of all web traffic.  In addition, its heuristics-based anti-malware technology is able to detect many zero-day malware variants.  More uniquely, the Gateway Anti-Malware engine offers inline, real-time, emulation-based sandboxing using behavioral analysis to identify never-before seen threats based on their behavior.  After analyzing the combined effectiveness of these technologies, we found that only a small percentage of web traffic could not be confidently identified as either safe or malicious – roughly 0.5%. This made the cost of delivering selective RBI for Risky Web something that could be easily absorbed without any additional cost to our customers.

Remote Browser Isolation is an absolute paradigm shift in how we can protect our most critical assets against web-based threats today.  While the benefits are tremendous, cost has been a significant barrier preventing this powerful defense from becoming a ubiquitous technology.  McAfee Enterprise has broken down this barrier by leveraging our superior threat intelligence to reduce the cost of delivering RBI and then passing this savings on to our customers.

Remote Browser Isolation

Remove the risk and enjoy worry-free web browsing with McAfee’s RBI.

View Now

The post Remote Browser Isolation: The Next Great Security Technology is Finally Attainable appeared first on McAfee Blogs.

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Ireland’s Gardai Clamps Down on HSE Cyber-Attackers

Ireland’s Gardai Clamps Down on HSE Cyber-Attackers

Ireland’s national police service, Gardai, has carried out a significant operation targeting the gang behind the ransomware attack on Ireland’s Health Service Executive (HSE) in May, which it believes has prevented other such attacks taking place globally. 

On Sunday, a spokesperson said: “A significant disruption operation which targeted the IT infrastructure of a cyber crime group has been conducted by the Garda National Cyber Crime Bureau (GNCCB).

“The Garda National Cyber Crime Bureau have seized several domains used in this and other ransomware attacks.” 

May’s ransomware attack on HSE, carried out with Conti ransomware, led to significant disruption to the Irish health service provider and many patients, costing the organization millions of euros. 

Gardai has used a so-called “splash screen” on the web domains to warn potential victims that ransomware has likely targeted their system.

The seizure of the websites reportedly “directly prevented” other ransomware attacks across the world.

“A process has also commenced between the Garda Siochana and their law enforcement partners at Europol and Interpol to provide the details of the visiting URLs to the member countries to ensure that the infected systems are appropriately decontaminated,” the spokesman said.

“To date a total of 753 attempts were made by ICT systems across the world to connect to the seized domains.

“In each instance, the seizure of these domains by the GNCCB investigation team is likely to have prevented a Conti ransomware attack on the connecting ICT system by rendering the initially deployed malware on the victim’s system as ineffective.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Pro-Russian Disinformation Systematically Spread Using Western Media Channels

Pro-Russian Disinformation Systematically Spread Using Western Media Channels

Western media channels are being systematically manipulated to spread pro-Russian government propaganda and disinformation, according to a new report by the Crime and Security Research Institute at Cardiff University.

The researchers said they uncovered evidence that “provocative” pro-Russian or anti-Western statements were being systematically posted in reader comments sections in articles relating to Russia in 32 prominent media outlets across 16 countries. Russian-language media outlets subsequently used these comments as the basis of stories about politically controversial events.

These stories insinuated there is significant support among Western citizens for Russia or President Putin, using headlines such as “Daily Mail readers say…” and “Readers of Der Spiegel think…” They were also picked up and reported by other ‘fringe media’ and websites with track records of spreading disinformation and propaganda, some of whom have been linked to Russian intelligence services by Western security agencies.

In one example highlighted by the study, a small number of comments in a Mail Online story about the Taliban’s takeover in Afghanistan were used in a Russian news article under the headline “The British have compared the rise of the Taliban to power with the end of Western civilization.”

These stories were primarily published in Russia and audiences in Central and Eastern Europe, particularly Bulgaria. In total, the team discovered 242 stories that they believe were generated in this fashion. Among the websites repeatedly targeted by the influence operation are The Daily MailDaily Express and The Times in the UK; Fox News and Washington Post in the US; Le Figaro in France; Der Spiegel and Die Welt in Germany; and La Stampa in Italy.

The report added that there was evidence of coordination between Russian state-owned media and outlets linked to the non-state Patriot Media Group, observed and drew upon these reader comments.

While these activities were first spotted as part of research into online disinformation amid tensions between Ukraine and Russia earlier this year, the Cardiff team believes these tactics have escalated since 2018.

The researchers used data science pattern recognition and detection techniques to reader comments to make their findings, which uncovered multiple unusual behaviors associated with some accounts posting pro-Russian content. These included some users repeatedly changing their personas and locations. At the same time, on specific platforms, pro-Kremlin comments received an unusually high number and proportion of ‘up-votes compared with typical messages. Together, these multiple inauthenticity signals suggest the commenting activity was coordinated.

Professor Martin Innes, director of the Crime and Security Research Institute at Cardiff University, explained: “As mainstream social media platforms have become more alert to the risks of foreign state influence operations, so disinformation actors and propagandists have been seeking new vulnerabilities in the media ecosystem to exploit. By adopting a ‘full spectrum’ media strategy that blends together information from social and mainstream media outlets, this sophisticated campaign has had the potential to shape the thoughts, emotions and behavior of several diverse international audiences in relation to high-profile media stories.

“Most importantly, the particular tactics and techniques used to ‘hack’ the comments function in the media ecosystem make it almost impossible to attribute responsibility for the pro-Kremlin trolling behavior on the basis of publicly available open-source data. It is therefore vital that media companies running participatory websites are more transparent about how they are tackling disinformation and more proactive in preventing it.”

Andy Patel, a researcher with F-Secure’s Artificial Intelligence Center of Excellence, said media channels must do more to prevent comments being posted by nefarious actors on their sites. He says: “Comments sections on news sites attract posts from users with extreme opinions, and thus often precipitate arguments. These discussions are ripe for abuse by trolls and entities wishing to further extremist agendas. The research published by Cardiff University illustrates how such discussion threads can also be weaponized by bad-faith actors. Comments sections on sites such as these should be properly moderated. If this is not possible, the responsible thing to do is to disable comment functionality until proper moderation policies can be put in place.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

US Cyber Command: Patch Critical Atlassian Bug Now

US Cyber Command: Patch Critical Atlassian Bug Now

US government security experts have urged system administrators to patch two critical flaws in widely used Cisco and Atlassian products, exposing them to compromise.

In a rare move, US Cyber Command took to Twitter before the Labor Day holiday weekend on Friday to address the Atlassian bug.

“Mass exploitation of Atlassian Confluence CVE-2021-26084 is ongoing and expected to accelerate. Please patch immediately if you haven’t already—this cannot wait until after the weekend,” it warned.

Atlassian issued a patch for the vulnerability in its popular web-based collaboration platform on August 25. The developer said that if exploited, the Open Graph Navigation Library (OGNL) bug would allow an unauthenticated user to execute arbitrary code on a Confluence server or datacenter instance.

OGNL was also exploited by the attackers who breached Equifax in 2018 via Apache Struts 2 vulnerability CVE-2018-11776.

Also, at the end of last week, the Cybersecurity and Infrastructure Security Agency (CISA) issued an alert urging admins to patch a critical vulnerability affecting Cisco Enterprise Network Function Virtualization Infrastructure Software (NFVIS).

Impacting version 4.5.1 of the product, CVE-2021-34746 could allow a remote attacker to take control of an affected system.

“This vulnerability is due to incomplete validation of user-supplied input that is passed to an authentication script,” Cisco explained.

“An attacker could exploit this vulnerability by injecting parameters into an authentication request. A successful exploit could allow the attacker to bypass authentication and log in as an administrator to the affected device.”

There are no workarounds to address the vulnerability, leaving patching as the only option for impacted organizations.

The two alerts came as US government experts warned that ransomware threat actors are increasingly likely to strike ahead of holiday weekends.

Alongside prompt patching, national security advisor, Anne Neuberger, recommended organizations deploy multi-factor authentication, up-to-date backups and strong passwords. She also recommended organizations to review their incident response plans.

If you liked this article, be sure to check out this upcoming Online Summit session:

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

SEC: Beware Hurricane Ida Investment Scams

SEC: Beware Hurricane Ida Investment Scams

The US Securities and Exchange Commission (SEC) has warned investors not to fall for scams capitalizing on the Hurricane Ida recovery and clean-up operation.

The regulator’s Office of Investor Education and Advocacy claimed that disasters including hurricanes, floods and oil spills often attract opportunistic fraudsters, who use email and social media to promote their scams.

“These scams can take many forms, including promoters touting companies purportedly involved in clean-up and repair efforts, trading programs that falsely guarantee high returns, and classic Ponzi schemes where new investors’ money is used to pay money promised to earlier investors,” it explained.

“Fraudsters also may target individuals receiving compensation from insurance companies.”

The SEC said it took several enforcement actions against individuals and companies trying to cash in on the aftermath of Hurricane Katrina in 2005.

Some made misleading statements about the potential high-profits their companies could reap from clean-up efforts to inflate their share price and facilitate classic “pump and dump” scams.

“One of the best ways to avoid investment fraud is to ask questions. Be skeptical if you are approached by somebody touting an investment opportunity. Ask that person whether he or she is licensed and whether the investment they are promoting is registered with the SEC or with a state,” the regulator urged.

“Check out their answers with an unbiased source, such as the SEC or your state securities regulator. Know that promises of fast and high profits, with little or no risk, are classic signs of fraud.”

In terms of volume, investment scams numbered only around 8,800 last year, putting them in the bottom half of the most common types of cybercrime by victim count, according to the FBI.

However, they ranked at number three in total losses, costing victims over $336m in 2020. That puts the category behind only romance scams ($600m) and Business Email Compromise ($1.9bn).

If you liked this article, be sure to check out this upcoming Online Summit session

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains

Dallas School District Reveals Major Data Breach

Dallas School District Reveals Major Data Breach

One of America’s largest school districts has informed students, alumni, parents and employees that personal data from the past 11 years was exposed after a third-party gained unauthorized access to it.

The Dallas Independent School District (ISD) claims to serve 145,000 students in 230 schools across the region and boasts 22,000 employees.

However, it revealed last Friday that it was notified about a data security incident on August 8. Although the district is still working out which data was exposed for each victim, students, employees and contractors between 2010 and the present were likely affected.

“An unauthorized third party accessed our network, downloaded data, and temporarily stored it on an encrypted cloud storage site. The data have since been removed from the site,” it noted.

“To date, our cybersecurity experts have found no evidence indicating the data was otherwise accessed, disseminated, or sold. However, we cannot be 100% sure until our ongoing investigation is complete.”

The breached data includes full names, addresses, phone and social security numbers, dates of birth and employment and salary info for current and former employees and contractors.

For current and former students, it includes full names, social security numbers, dates of birth, parent and guardian info and grades. According to the alert, some students’ custody status and medical conditions may also have been exposed.

The district is offering 12 months of credit monitoring and ID theft recovery services and said it is continuing to investigate and remediate the incident. However, it’s still unclear what the attacker’s motives were.

“We confirmed that the unauthorized third party removed the data from the encrypted cloud storage site and has informed us the data was not disseminated or sold to anyone,” Dallas ISD claimed.

It’s also not clear how the attacker managed to access the electronic records, although the district claimed that its IT team had been working with forensic experts to fix “specific vulnerabilities that were exploited during this event.”

—————
Boost Internet Speed
Free Business Hosting
Free Email Account
Dropcatch
Free Secure Email
Secure Email
Cheap VOIP Calls
Free Hosting
Boost Inflight Wifi
Premium Domains
Free Domains