Cyber Security - the emerging lifeline

Cyber security is emerging as the life in the digital world.

Management Education

Management education has become critical in this hyper active world filled with dynamics.

Cyber Security training

Cyber security calls for intricate understanding

Police trained in Cyber Security

Cyber Security Calls for a series of awareness programs followed by diploma and degree programs

Cyber World !

Cyber World is composed of various interdependent components.

Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Thursday, January 3, 2013

PlugX and its implications

A new Remote Administration Tool has been discovered called PlugX which is a Remote Access Tool (RAT). It has also been named as Korplug. PlugX has been detected in targeted attacks not only against military, government or political organizations, but also against more or less ordinary companies. The attack starts with a phishing email containing a malicious attachment, usually an archived, bundled or specially crafted document that exploits either a vulnerability.
PlugX has been witnessed to be delivered with the three file components, namely:
  • A legitimate file
  • A malicious DLL that is loaded by the legitimate file
  • A binary file that contains the malicious codes loaded by the DLL.

Wednesday, January 2, 2013

Shamoon attack


A new malware surfaced during August 2012 as reported by the various security agencies.  The malware has been  dubbed by the code name  "Shamoon". The attack is called "Shamoon", due to a filename i.e. string of a folder name within the malware executable called as Shamoon. ("C:\Shamoon\ArabianGulf\wiper\release\wiper.pdb").The spyware infects all the computers in an internal network.

The main executable contains 3 resources, each maintains a ciphered program. PKCS12:112, PKCS7:113 and X509:116,  according to Dmitry. Symantec said that the malware, which it calls "W32:Disttrack," had infected fewer than 50 machines worldwide. The main Shamoon module has a resource PKCS7:113 that maintains an executable which is saved to disk as %WINDIR%\System32\NETINIT.EXE says Dmitry Tarakanov. He adds that the malware waits for CNC communication as evident from its communication module. He also talks about PKCS12:112 another module playing an important role. The details of shamoon's operation is explained  by Dmitry here.  Shamoon, is being used in targeted attacks against at least one organization in the energy sector, according to Symantec.

Tuesday, January 1, 2013

Mariposa Botnet


Understanding Bots as a technology has emerged as a critical skill in the information era. This article is focused in understanding Mariposa. Botnet Mariposa was reported by defense intelligence some time during May of 2009. Trend micro says that the worm has been in existence as early as December 2008. It is learnt that the reported botnet was named after the Spanish word for "butterfly" as documented across the Internet. It had silently enrolled almost 13 million computers in more than 190 countries. 

Friday, April 6, 2012

Sality

Sality is a file-infecting virus that has been around for more than nine years. Sality has been ranked by Symantec as the number one malicious code family in 2010 by number of endpoint detections. It was apparently named after the Russian town of “Salavat City”, although the command and control servers are thought to be in the US, UK, and the Netherlands. It has been used to push spam, steal passwords, crack SIP accounts, and various other nasty things. 

Zeus botnet - Operation b71

Zeus, often referred as Zbot is one of the popular crimeware  botnet typically engaged in data theft.  The term Zeus is used to refer to an entire family of trojans and their respective bot nets. It was reported by 2007. Zeus botnets are fundamentally simple computer networks otherwise called as a group of interconnected computers,  built by a group of interested parties with a criminal motive,  using the Zeus infection crimeware toolkits. The Microsoft blog claims that it has detected more than 13 million suspected infections of this malware worldwide, with more than 3 million in the United States alone.

For a better understanding, Zeus is a toolkit pack which aids a the user with a tool set required to build and administer a botnet. These tools are designed with a focus of stealing banking information. However they can also be used used for other types of data or identity theft.  The toolkit is a marketable product of commercial value, which is sold to potential customers. They are also distributed freely. Like most botnet families, standards framework, Win32/Zbot is built on the client-server model and requires a command and control (C&C) server to which the bots connect to receive instructions from the botnet operator.

Tuesday, March 20, 2012

Digital Cyber Forensics: Conference related info


The Internet has made it easier to perpetrate crimes by providing criminals an avenue for launching attacks with relative anonymity. It is evident that  illegal activities are more often buried into large volumes of data which calls for extensive analysis in order to detect crimes and collect evidence. Most of the time the investigations are of cross-border in nature, requiring coordinated policing  efforts in heterogeneous jurisdictions.

Security: Know your APT

Advanced Persistent Threats (APTs) has been estimated to grow faster than other technologies. APT is a a part of the classified category of cyber crime directed at  business at large and / or political targets. They are built with a high degree of stealithiness over a prolonged duration of operation in order to be successful. APTs are built with a fixed goal of remaining invisible as long as possible. As such, tahe APT operators tend to focus on “low volume” attacks and over time they would have covered a large area,  stealthily crawling from one host to the next as it is being compromised., and ensuring to avoid generating regular or predictable network traffic. Damballa predicts that the volume of persistent attacks directed at large corporations will continue to increase and the victims will continue to feel as though they have been specifically targeted in the year 2012. McaFee is clear in commenting that the solutions in silos don’t enrich each other with relevant data and introduce greater complexity to analysis and remediation, giving the advantage to the perpetrators of the APT. 

Security: Know your DNS

The Domain Name System (DNS), has been defined by RFCs 1034 and 1035. It is a  hierarchical, and distributed database used for providing a service to resolve names for various Internet applications. A zone as understood by everybody is a collection of nodes, forming a contiguous tree structure, with  the start of authority, or SOA. The purpose of SOA is to delegate the naming authority downward, to delegation points, terminating with leaf nodes. The elements of the SOA are made available from the DNS authority servers to recursive DNS servers.

Sunday, March 18, 2012

Cyber Operations - Ghost Click


The largest internet cyber sting operation taken by FBI was named as Ghost click. Since 2007, a group of cyber group had deployed a special class of malware called DNSChanger. It is understood that the FBI had arrested six Estonians accused of running a botnet that controlled more than 4 million computers in 100 countries equating  the infections to approximately 4 million computers. It is estimated that there were more than 500,000 infections in the U.S. alone, in a composition of computers belonging to individuals, businesses, and government agencies such as NASA.


Thursday, March 15, 2012

Digital Warfare - Use of struxnet is a test run or failed mission? Speculations are ON?

The birth of struxnet has opened up an New era of  discussions in the security community. Since its discovery earlier this year, the sophisticated Stuxnet worm has infected at least 15 industrial plants in a variety of countries. Security experts have universally accepted that the the worm had the ability to target a  specific computer and inflict damage to controls equipment at industrial facilities.

Digital Warfare - Duqu: Struxnet family of BOTS

Stuxnet, the first military-grade cyberweapon known to the world.  Stuxnet was believed to have been released in late 2009 and millions of computers were infected as the worm though there are other references which claim that it was release as early as 2007. Stuxnet was designed to cripple control systems. The list of modules built as a part of Struxnet provide different kinds of permutations and combinations to reassemble the code with variations. One such example was the birth of Duqu.
Duqu, acts as a Trojan, stealing data, potentially acting in the planning stages of an attack. It can be said that DuQu was used as an intelligence gathering tool, possibly  aiming to prepare the ground for future attacks.  According to Alex Gostev, the main module consists of three components:
  • a driver that injects a DLL into system processes;
  • a DLL that has an additional module and works with the C&C; and
  • a configuration file.


Wednesday, March 14, 2012

Digital Warfare & Struxnet - Where are we in security?

Enisa has come up with a statement that Stuxnet is a specialized malware targeting SCADA systems running Siemens SIMATIC® WinCC or SIMATIC® Siemens STEP 7 software for process visualization and system control.  The software consists of a series of software block, which are combined into a project.Some of the blocks include Function blocks, Operational blocks, and Data blocks. These software system command the components that control speed in gas-enrichment centrifuges, used for separating radioactive isotopes by spinning at supersonic speeds.


Tuesday, March 13, 2012

Cyber threat Stuxnet & Big data analysis


Cyber threat to national economy is an emerging menace. Countries world wide have started realizing this and have taken their stand. What was once a war on the land is getting shadowed as history.  The new sophisticated warfare has opted for cyber weapons as their gadgets. For example the same blog has mentioned about Federal Trojan and its capabilities. The Trojan was used to intercept skype transactions and other such online transactions. 

Saturday, March 3, 2012

Federal Trojan

Federal Trojan aka R2D2 is considered to be one of the SKYPE interceptors as understood from the register. This trojon is also called by other names "0zapftis" or "Bundestrojaner",This trojan has the capability of running on 32 bit systems; with support for 64 bit versions of Windows. The technology works via a local installation of malware on the clients computer. BOTs and Trojans are  classified generally under Malware.