Saturday, September 1, 2012

The Saudi Aramco cyber attack points to new arsenal in a Hacktivists armoury


On August 15, 2012 a virus infected 30,000 desktops of the world largest oil producer Saudi Aramco, forcing disconnection of its IT systems from the external world, and the launch of a massive exercise to cleanse the infection. The primary objective of the virus was to erase all data from hard disks and report the deleted file names to an external control center.  The attack was undertaken by a group calling itself the “Cutting Sword of Justice” which said in an ideological post on Pastebin, that it was “fed up of crimes and atrocities taking place in various countries around the world”.

Saudi Aramco is one of the largest petroleum producing companies and accounts for a significant portion of the Saudi economy.  The hackers chose a Critical National Infrastructure target which is the largest financial source for the Al-Saud Regime.  A major disruption of Aramco’s oil production networks would consequently have had a direct impact on global energy supplies and the global economy. Aramco reported that it had air gapped its oil production network thereby preventing damage to its oil production assets.

In past attacks like Stuxnet, the development of similar malware was primarily attributed to government funded units, but in this case the incident seems to suggest that the virus was developed by a hacktivist outfit.  If true, it indicates a new and disturbing trend as previous Hacktivist methods were limited to the more mundane denial of service attacks or hacking into web sites.

Antimalware products have also once again demonstrated how deficient they are in defense against custom malware.

Sunday, August 26, 2012

A Naked Prince, Spy Cams and a big Hangover


The very recent episode of “The Naked Prince in Las Vegas” amply demonstrated the commercial value of a celebrity's personal life.  The party girl, who revealed naked snaps of Prince Harry online, has reportedly been offered a 1 m$ package for the mobile footage of the entire party.   Was the secret filming planned or simply opportunity seized! I guess we will never know.

Privacy can easily been compromised with a mobile or spy camera. There have been many instances of where such footage has been used for blackmail, sold to porn sites or used by media.

Celebrities are most at risk, when they move out of closed social circles and try to socialise like normal people.  It must be difficult for royalty, who are caught between the need to adhere to tradition and personal life.

Tuesday, July 31, 2012

London Olympic 2012 Security and the Mysterious Woman leading the Indian Contingent


Hosting an event like the Olympics’ requires a large number of security personnel to operate x-ray machines, search vehicles and stand guard at venues. For the London 2012 Olympics over 10,000 personnel required to be recruited and trained to prevent theft, activism and unruly activity. Mobilizing an enormous workforce via temporary recruits or volunteers is an expensive affair for short events, which usually results in poor or hurried training of personnel, and inadequate background checks. It is not possible to recruit well in advance due to the large numbers and need to contain staff costs. It may be said that the temporary workforce is used more for mitigation of risks rather than removal of it, with the prime responsibilities for security resting on the more qualified forces such as police and military and their use of a defense in depth security cordon to protect athletes and people in venues.

When I read about the mysterious woman who walked alongside flag bearer Sushil Kumar in red track top, blue pants and sneaker smiling, waving and soaking in the moment as the Indian contingent walked the track it indicated a brazen gate crash into what should have been considered the inner sanctum of the security perimeter.  

In this case, it turned out to be a protocol breach. An over eager Indian student volunteer taking up the opportunity to walk with the team. But it also indicated a large failure of the security apparatus, volunteer training and supervision of volunteers. The same security vulnerability could have been exploited by terrorists for malicious ends.

Sunday, July 8, 2012

Use of infected Thumb Drives (USB Drives) is a major security weakness

Thumb drives are extremely popular due to their portability, convenience and low cost.  Computer users, at home or at work cannot do without a thumb drive for sharing digital data such as files or music.  Drives have become so cheap that product vendors freely distribute them at product conferences as giveaways or as repositories of digital product literature.  Any digital product with a USB port and storage capacity can be converted into a digital drive.  A common example would be the ubiquitous smart phone.  Thumb drives have also become fashion accessories with drives disguised as pendants and pens making them harder to detect.

Most companies prohibit or regulate the use of USB ports and the devices that can be connected to them. The US Government has forbidden the use of such devices in Government and Defense departments post Wikileaks.  USB’s are used in targeted attacks to compromise systems which are physically isolated from the Internet or external networks. Stuxnet, a cyber weapon which destroyed Iranian centrifuges spread through a compromised USB drive.  In a more recent case, the Indian Eastern Naval Command was infected by malware which allegedly spread through a compromised USB. According to news reports “The malware is then thought to have created a secret folder on the drives where it stored documents, and as soon as the drive was plugged into a computer connected to the web, it sent the files to specific IP addresses”.

Users of USB drives face the risk of mass malware designed for cyber crime involving spam or financial fraud or the more targeted variety for espionage or cyber destruction. Malware normally propagates by copying itself onto clean drives inserted into infected computers. There is a probability of mass infection if the drive is infected at production or when digital data (such as product brochures) are mass copied onto several thousand drives.

 In both these cases, the common elements are a lack of security awareness or the pressure of a deadline causing individuals to override the fundamental security principle of not using third party USB drives, and an over reliance on antimalware products to detect malware. Antimalware products have limited success in instances where the malware is custom designed for select targets.

 In the case of the Iranian Stuxnet infection or the Indian Naval Leaks, the key introspection point was the method in which the compromised drive entered the premises. These installations are highly secure and forbid the use of outside drives (non registered drives), therefore the use of an unauthorized drive or the compromise of an internal drive needs detailed investigation into the human element and motive behind it. It is an indicator that the technical methods to prevent motivated individual using such drives was not as restrictive as it needed to be.