Sunday, January 27, 2013

Week 7- My Insights

The assignment this week was pretty straight forward.  For this assignment most of my current security threats and vulnerabilities were gathered from Verizon's 2012 Breach report in which can be found at:  http://www.verizonbusiness.com/resources/reports/rp_data-breach-investigations-report-2012_en_xg.pdf  It seems that most of the vulnerabilities and threats discovered in the Harry & Mae's Case Study were current security trends found in the Verizon report.  It amazing how something as simple as failure to change default settings on a device can lead to a huge loss for business if exploited.  A company like Harry & Mae's that handles customers credit card numbers can't afford to be careless with this information.  They can lose there privileges to process credit card payments and be forced to pay huge fines.  This is a risk that as a business owner I would not want to accept.  Listed below are a few of my findings from the Harry and Mae's case study that I think are important yet simple fixes. 
Findings Summary
·        Default settings are currently being used throughout the network on various devices making it easy for hackers to break into network devices and capture information such as customer data, usernames and passwords.  It also makes it easy for hackers to establish user accounts and create privileges for themselves that allow them to have full access to the network or that particular device. 
·        Company wireless network is not password protected making it easy for hackers to compromise network and capture information being shared across network.  This includes the capturing of usernames and passwords.
·        Firewalls are not enabled making it easy for hackers to obtain reported information from malicious software that may be installed on the network without sending an alarm or alert.  Traffic is allowed to flow in both directions.    
·        Signature files are not being updated to filter e-mails.  Virus firewall will only capture e-mail according to old files and any new threats will not be captured.  This opens the network up to malicious software and viruses. 
·        No password restrictions.  This allows users to create easy and simple passwords that can easily be cracked by brute force or that can be easily guessed.  Uses are also writing passwords down making it easy for other employees, janitors, or visitors to login and compromised the system.
·        Virus software not currently being used on virtual servers. 
·        Access card data is being stored on the server that’s not protected.  If server was compromised hackers can create fake access card accounts to gain access to the building.  This in return will create a physical breach which could not only case harm to data but employees as well. 
·        Public IP address being used on servers making them accessible to those outside the network.
·        FTP server being used by employees to transfer files from outside and inside the company.  This makes it easy for employees to steal files from work or bring in malicious software or viruses to be distributed across the network. 

Sunday, January 20, 2013

Week 6

In my week 2 blog I posted a list of sources that I felt were credible and reliable sources for obtaining information on potential threats and vulnerabilities.  The sites listed were good sources for security news and issues.  After reviewing my blog posts from previous weeks these are actually the sources that I have been using regularly.  Last week I used one sources that was outside my list and that was www.cio.com.  I think this may be a good sources to add to the list in that it contains information on the best products to include apps and tablets.  It keeps you up on what's going on with companies such as Microsoft and Apple. 

Sunday, January 13, 2013

Week 5- Harry & Mae’s Assumptions

There are many assumptions to be made about Harry & Mae’s incorporated when it comes to security.  Security is something that they lack and I think they should consider developing some type of procedures, policies, and standards in order to protect the company’s assets.  There is also nothing in place that deals with privacy in the work place and therefore employees can’t be held liable for their actions.  There should be something in place to make employees for their actions in the workplace.  Harry & Mae’s should also be thinking about protecting their reputation as well.  An open network can compromise the integrity of the data being stored and retrieved.  They should also consider disgruntle employees in that they are known to cause major damage to the company.  The article listed below provides a few myths in the workplace that all employees should consider while on the job.  These should also be considered for Harry & Mae’s.  The article can be found at:  http://www.securityweek.com/three-privacy-myths-workplace

Sunday, January 6, 2013

Week 4 - Fake Netflix Android App


Over the past few years’ cell phones have evolved from talk only to talk, text, and Internet.  Cell phones today are like compact computers and can be used to do just about anything that a desktop computer can do.  You can use them to shop, play games, check bank accounts, transfer money, pay bills, e-mail, and chat, watch movies, listen to music, and many other cool things.  However, this rapid increased use has made cell phones a target for scammers.  The android app market is a place where users can download different apps.  Some apps are free and some require a small fee for use.  From my understanding anyone can build an app and publish it.  You don’t have to use Google play, but you can use other app markets to publish your app.  This is scary in that as a user you don’t know if the app being downloaded contains malicious software.  If the downloads does contain malicious software it can be used to gather passwords and account information from your phone.  In other words if you use your phone to pay bills, shop, or do anything that requires the use of a password the bug will capture that information.  I found this article that talks about how a fake Netflix app was created that contained a Trojan that could capture passwords and account information. This was a bogus app that had the potential to affect thousands of devices.  Netflix is a huge company that used by many to download and stream movies.  How can a user know if the apps they are downloading are safe?  The article can be found at:  http://www.cio.com/article/691743/Fake_Netflix_Android_app_is_social_engineering_scam

Sunday, December 16, 2012

Week 3- New ‘Dexter’ malware strikes point-of-sale systems

Many of us use our credit and debit cards to make purchases at many stores to include hotels and we do so sometimes not really thinking about the risk associated with doing so.  We assume that point-of-sale systems are secure and safe and we don’t think about the fact that these systems can be attacked like any other system.  Why?  Because they contain credit and debit card data of every card that has been swiped for purchases.   According to an article titled “New ‘Dexter’ malware strikes point-of-sale systems” written by Charlie Osborne hundreds of POS systems have been affected with malware.  The malware called “Dexter” has affected systems in over 40 countries with 30% of the infections taken place in the US.  Dexter is designed to steal credit card numbers and data.  Dexter is designed to target POS systems by injecting itself into the iexplore.exe in Windows Server.  It then takes credit card data from the server and sends it back remotely.  At this point the hackers can produce fake credit cards using the credit card numbers retrieved from the server.  Majority of the operating systems infected have been Microsoft products with Windows XP being the most targeted.  So far the names of the business affected have not been released.  The article can be found at:  http://news.cnet.com/8301-1009_3-57559171-83/new-dexter-malware-strikes-point-of-sale-systems/

Sunday, December 9, 2012

Week 2- Credible Sources

Not all web sites on the Internet are a credible source of information when it comes to threats, vulnerabilities, updates, and security news.  You can’t believe everything you read, watch, or hear on the Internet.  When there is a conflict within a source the best way to check it is to weight it against known reliable sources.  If the sources list vulnerabilities within specific software, the best way to check the source is to visit the venders’ web page.  This is true for patches as well.  In order to stay on the safe side I would recommend using governmental, libraries, known organizations, and universities as sources for information.  Vender sites are usually very helpful at providing credible information about securities issues associated with their products.  The following is a list of sites that consider to be credible sources because they are from professional organizations or have proven over the years to be credible sources for information.
·         Security Week  http://www.securityweek.com/virus-threats
·         CNET  http://news.cnet.com/security/
·         SC Magazine  http://www.scmagazine.com/
·         NIST  http://www.nist.org/news.php
·         SANS  http://www.sans.org/
·         Bit Defender  http://www.bitdefender.com/security/
The sites listed above are just a few of the many sites that I think are credible sources.  If you stick to sites such as the ones listed above the information you receive should be reliable.  If you are unsure about a source you can also do some research on the author and check any references that he/she may have used in their article or document. 

Monday, December 3, 2012

Week 1 - Managing Threats in the Digital Age


The digital age has opened the door to more threats due to increased Internet usage.  We use the Internet to conduct business, work, education, travel plans, entertainment, and personal use.  The devices used to access the Internet have increased as well.  Not only do we connect to the Internet via desktops but we can also use our cellphones, iPods, iPads, notebooks, PDAs, and other mobile devices.  The use of these devices along with the increased use of the Internet has created many security challenges.  These challenges can be categorized into three categories and they are external threat, internal threats, and compliance requirements.   These challenges make managing threats a big priority especially for governmental and major organizations like financial institutes and hospitals.  They all collect and store a lot of sensitive, classified, or personal information that could cost them billions of dollars in losses.  These loses can range from ruined reputation, legal fees and penalties, and revenue due to system downtime.  I found this article titled “Managing threats in the digital age” that covers a lot of important information about managing threats.  The article talks about how you need to be proactive when it comes to security.  In other words when it comes to security organizations should implement real-time monitoring for identifying, tracking, and addressing threats.  This would include real-time audits and monitoring of employee usage.  I must say that I agree with the article.  Many security threats are usually detected after the fact and not during.  Most of the breaches are usually detected days or months after the breach.  It’s the same for monitoring employee actions.  It usually takes a few months or days before they discover that and employee was copying files.  It would be nice to be able to monitor employees for system misuse. 
The article can be found at: http://public.dhe.ibm.com/common/ssi/ecm/en/gbe03423usen/GBE03423USEN.PDF