Thursday, 24 September 2015

Applying Data Science to Advanced Threats

The Problem

The cyber security industry is now over 30 years old. And just like people, with each passing decade, we realize that what worked for us in our 20s, simply won’t work for us now or going forward. In fact, carrying forward the mindset and behaviors of those first 20 years exposes us to countless problems in health and long term solvency. We learn that to survive in the world we must adapt and evolve to a higher form of existence. The antiquated and archaic practices of our past limit our visibility into the future in detecting, and thereby avoiding, maliciousness. Consequently they have given rise to a freight train sized hole of opportunity for the cyber criminals, nation states and cyber miscreants that wish to exploit our blindspots in the cyber world.

Blacklisting (and Signatures) Can Be Compromised

Blacklisting technologies rely almost 100% on signature based techniques for detecting bad files have been at the heart of our industry since the beginning when we had only rare outbreaks like Michelangelo, Stoned and the Morris Worm. The grossly unfortunate fact is that they remain the predominant form of detection (and thereby prevention) in the market today. Signature based approaches to security served us well then when the number of bad objects (files, network traffic, and vulnerabilities) was small and the techniques to alter those files to bypass detection were non-existent or at least non-trivial.

Today however, countless techniques exist to avoid these once stalwart protection technologies, including packers, mutation engines, obfuscators, encryption and virtualization bypass techniques.

Within milliseconds, a once easily detected malicious file can be altered to be completely invisible to even today’s best detection technologies while remaining functionally identical to its original maliciousness. This allows the bad guys to easily bypass security infrastructure that once detected them with ease.

The sheer numbers of files submitted to security vendors today for analysis (over 100k daily) is so overwhelming that most vendors simply cannot handle the volume. Their methods and manpower become easily avalanched over. The scale of the problem outnumbers the industry’s capacity for maintenance. As a result we have rampant miss rates.

Whitelisting Can Be Compromised

Whitelisting technologies developed in response to what the Blacklisting world is victim to: low detection rates. In other words, blacklisting alone detects only 5-10% of malicious files out there. The reason whitelisting was so promising for so long was that it effectively did the opposite of blacklisting: rather than stopping everything known bad (which is large and hard to do), whitelisting only allowed to run those files which are known good (which is much smaller and presumably easier to do). This technique has been applied to security through identification of permissible URLs and files that are known (or perceived) to be clean and safe. But these solutions have some fundamental problems as well.

The first challenge with solutions that rely heavily on whitelisting is that one must simply “trust” what the vendor (or your operations staff) has designated as “good”. We have seen this model fall down time and again with security and software vendors who have their development environments compromised and their private signing certificates stolen (e.g. Adobe, Bit9 and Opera Software). When these attacks occurred it allowed the thief to sign their own malicious files as if they came from the “trusted” vendor. And because whitelisting solutions rely so heavily on this “trust” model, it allows the bad guys to easily bypass the technology.

Trust Can Be Compromised

As a consequence to the identified gaps of blacklisting and whitelisting, numerous technologies have crept up to fill in the gaps of signature technology including host intrusion protection systems (HIPS), heuristics, behavioral, and both hardware and software sandboxing. But all of these techniques have two core weaknesses: 1) foundational signature elements, and 2) reliance on “trust”.

Technologies such as HIPS, heuristics and behavioral engines remain at their core, signature based. They rely on “knowing” what is bad and creating a signature for that “badness”. Even sandboxing technologies which claim no signatures are involved to autodetonate captured files and binaries, still rely on signatures to enable alerting and blocking the next time it sees it.

For these technologies to know if something is good or bad, they must map them to a list of known good or bad behaviors which can take minutes, hours, or days using manual verification. Even then, the attack has already happened and the detonation may not discern the maliciousness of the malware.

Can we simply “trust” our vendors to show us what is “good”?

Bad guys have the advantage in more resources and time to outwit the various detection schemes of security vendors. Additionally, many security models (like signatures) require the engagement of a human. Human involvement is fallible and limited in scale to the speed and sophistication of advanced threats.

Can we simply “trust” our security vendors to show us what is “bad”?

We as an industry must evolve from this outlived model to a new and ever-evolving technique; one that abandons signatures and blind trust; one that relies on a mathematical, algorithmic and scientific approach to better effectiveness and measurable accuracy. In short, we must evolve to “Trust the Math” and science of Cylance’s Infinity.

Introducing Cylance Infinity

Infinity is a fundamental and epic shift from traditional security methods of detecting good and bad. It is a highly intelligent, machinelearning, data analysis platform.

As battle tested security industry veterans, we know that the previous approaches can never cope with the volume and variety of advanced threats. So we designed Infinity to make intelligent decisions without relying on signatures. It does this by taking a predictive and actuarial approach to data on a network to determine good from bad.

This model exists in many other industries. Insurance companies use actuarial science to determine the likelihood of a risk event for the insured person at a surprisingly high rate of accuracy. This concept relies on advanced models of likely outcomes based on a variety of factors. For a standard insurance policy, they may consider twenty to thirty facts to determine the most likely outcome and charge appropriately. Infinity uses tens of thousands of measured facts harnessed across millions of objects to make its decisions, in near real-time.

Infinity, at its heart, is a massively scalable data processing system capable of generating highly efficient mathematical models for any number of problems.

Cylance uses these models applied to ‘big data’ to solve very hard security problems with highly accurate results at exceptionally rapid rates. It’s done by applying data science and machine learning on a massive scale. Coupled with world class subject matter experts, cyber security is able to leap ahead of threats.

While Infinity is problem agnostic, correctly designing solutions to hard problems takes time, knowledge and effort. The Cylance Infinity Labs team has focused all of their efforts on detecting advanced threats, in near real-time, correctly, without signatures.

While Infinity is problem agnostic, correctly designing solutions to hard problems takes time, knowledge and effort. The Cylance Infinity Labs team has focused all of their efforts on detecting advanced threats, in near real-time, correctly, without signatures.

What is Machine Learning?

Machine Learning (ML) is a formal branch of Artificial Intelligence and Computational Learning Theory that focuses on building computer systems that can learn from data and make decisions about subsequent data. In 1950, Alan Turing first proposed the question, “Can computers think?” However, rather than teaching a computer to “think” in a general sense, the science of machine learning is about creating a system to computationally do what humans (as thinking entities) do in specific contexts. Machine Learning (ML) and big data analytics go hand-in-hand so ML focuses on prediction, based on properties learned from earlier data. This is how Infinity identifies malicious versus safe or legitimate files. Data mining focuses on the discovery of previously unknown properties of data, so those properties can be used in future ML decisions. This means Infinity learns on a continual basis, even as attacker methodologies change over time!

How it Works

Infinity collects data, trains and learns from the data, and calculates likely outcomes based on what it sees. It’s constantly getting smarter from environmental feedback and a constant stream of new data from all around the world. To achieve its magic, Infinity performs the following steps. First it COLLECTS vast amounts of data from every conceivable source. Second, Infinity EXTRACTS FEATURES that we have defined to be uniquely atomic characteristics of the file depending on its type (.exe, .dll, .com, .pdf, .java, .doc, .xls, .ppt, etc.). Third, Infinity constantly adjusts to the realtime threatscape and TRAINS the machine learning system for better decisions. Finally, for each query to Infinity, we CLASSIFY the data as good or bad.

Infinity – The Rubber Meets the Road

Infinity be used to supercharge decision making at endpoints, and woven tightly into existing security systems via a variety of integration options. It is cloud enabled (but not cloud dependent) to support advanced detection on a global scale in limited form factor environments, or can operate autonomously while still achieving a stunning rate of protection.

The breadth of deployment options helps to solve several fundamental problem points on a modern network.

CylanceV and CylanceV Local

CylanceV is a REST SSL Application Programing Interface integration to Infinity’s intelligent cyber security decision making. Through the API and specially developed utilities, IT departments executing incident response and forensics can take the tedium out of tracking down malware and determining what is truly bad.

CylanceV enables a starting point for forensic analysis and timely remediation through an automated and highly efficient approach.

Tying other security tools like SIEM, Log analysis, host and network monitoring, HIPS/NIDS and investigation tools including anti-virus, anti-malware and forensics, into CylanceV provides contextual intelligence for more accurate and effective malware identification.

The CylanceV API allows utilities to be developed in most popular frameworks (.NET, Python, etc.) and invoked through HTTPS using tools such as CURL or WGET in order to make the data segmentation easier and more efficient.

CylanceV Local is an on-premise version of CylanceV that allows for use in restricted and sensitive environments.

Integrating 3rd party functionality, like Python scripts, Splunk, C# to Infinity quickly determines what is safe and what is a threat, making smart security smarter. Together, they reduce the total number of prospective compromised machines to something manageable.

Infinity On the Endpoint

CylancePROTECT is our host based security solution built on Infinity technology. It leverages algorithmic science to greatly increase the speed and accuracy of host protection without reliance on signatures, heuristics or behavior modeling. It offers a real-time protection layer on the endpoint that can make decisions about the nature of malware independent of connecting to Infinity and at a stunningly low performance impact. PROTECT offers a powerful front line of defense, whether your assets are behind your corporate firewall or in a coffee shop. Its extensive management capabilities easily blend the pervasive protection into your existing security workflow.

Summary

With Infinity, we can definitively determine good or bad file objects milliseconds, with extraordinarily high detection accuracy and extremely low false positive rates. Because the system is self-collecting, self-training, and selflearning, we always stay ahead of the changes and unknowns attempted by the bad guys. With such a mathematical approach, we may change the game of security… forever.

About Cylance

Cylance is a global cyber security products and services company headquartered in Irvine, California. Its founders, Stuart McClure and Ryan Permeh, know that today’s network and operations infrastructure is inadequately protected by flawed security.

Stuart is a leading authority in information security and lead-author of “Hacking Exposed: Network Security Secrets and Solutions”. Stuart launched the vulnerability assessment leader Foundstone, Inc. and served as Global CTO at McAfee as well as EVP/GM of the Security Management Business Unit.

Ryan is a leading expert in development of security technologies who, with Stuart, built TRACE, McAfee’s elite threat team, and unique detection technologies. Both have witnessed the security industry’s evolution firsthand over the past 25 years and know that the security infrastructure for today and tomorrow’s threats is fundamentally broken.

Cylance is driven by an impressive team of veteran Security executives, board of directors and advisors, and deeply talented security professionals to achieve a simple mission: Solve the world’s most difficult security problems

Cylance, Inc.

+1 (877) 973-3336

sales@cylance.com

www.cylance.com

West Coast Office: 46 Discovery, #200 Irvine, CA 92618 USA

East Coast Office: 11710 Plaza America Drive, # 2000 Reston, VA 20190 USA

To learn more about Cylance visit their website at www.cylance.com



from cyber security caucus http://ift.tt/1gQsjgo
via IFTTT

CYBERSECURITY LEADS AS CHINA’S PRESIDENT VISITS US TECH HUB

All eyes were on Seattle on Sept. 23 as Chinese President Xi Jinping prepared to deliver a speech to a group of Silicon Valley’s top executives.

But many experts doubted how much progress will actually be made from the meeting, CNBC reported.

As part of Xi’s weeklong U.S. tour, which will include stops at the White House and New York, he will meet with corporate CEOs at an Internet industry forum hosted by Microsoft.

“I expect a lot of diplomatic wording about how we’re learning to work together, but not a lot of progress,” Adam Segal, a senior fellow for China studies and director of the digital and cyberspace policy program at the Council on Foreign Relations, told CNBC.

Many are speculating Xi may discuss the allegations against his country for cyber spy actions, urge companies to oppose rumored sanctions from the White House or request that the firms comply with China’s government-mandated security policy.

Last week reports surfaced that American tech companies hoping to do business in the People’s Republic of China were reportedly being coerced into complying with an intrusive data and security policy.

According to The New York Times, Beijing sent a confidential letter to heads of U.S. tech companies asking the companies to ensure that their products and services released in China are “secure and controllable,” which could potentially lead to backdoors into smartphones, Internet services and any other tech products released for Chinese consumers.

But during a Sept. 21 speech about U.S.-China relations earlier this week, U.S. National Security Advisor Susan Rice warned China to put an end to its own threatening cyber activities, The Wall Street Journal reported.

“This isn’t a mild irritation,” she said in her speech at George Washington University. “It is an economic and national security concern to the United States. It puts enormous strain on our bilateral relationship, and it is a critical factor in determining the future trajectory of U.S.-China ties.”

For several years, U.S. authorities have expressed concerns over the level and frequency of attacks believed to be originating in China. The country has been linked to some massive cybersecurity breaches recently, making it no stranger to cyberfraud accusations.

From the attack on health care provider Anthem, which comprised the data of as many as 78.8 million customer records, to the more recent data breach at the U.S. Office of Personnel Management that led to cybercriminals accessing over 21 million Social Security numbers, 19.7 million forms with data and 5.6 million fingerprint records, Chinese hackers seem to always be on the list of likely suspects.

In an interview this week with WSJ, Xi denied China’s involvement in the high-profile online data breaches, emphasizing a need for the global community to collaboratively work to “build a peaceful, secure, open and cooperative cyberspace on the basis of the principles of mutual respect and mutual trust.”

View the original content and more from this author here: http://ift.tt/1KAxvwI



from cyber security caucus http://ift.tt/1Fh9Cyp
via IFTTT

Businesses make moves in cybersecurity war

ALBANY, GA (WALB) –More South Georgia businesses are concerned about recent computer breaches, and are looking for ways to protect themselves from criminals.

Several businesses had their and their customers’ financial information recently stolen through computer hacks.

Now more business owners are taking steps to make sure it doesn’t happen to them.

Tommy Padgett of Dasher & Padgett Financial Advisors says criminal computer hacking in businesses has become “overwhelming”, and they are being proactive.

“It can happen anywhere and to anybody,” he warned. “What we’re trying to do is find out some additional ways to protect ourselves and to protect our clients.”

Padgett was one of dozens of business owners who attended a seminar by HighTide Technology, a cyber security company.

They said Albany small businesses are at risk.

High Tide Technology president Norman Chandler said

“Identities stolen through the fraudulent filing of tax returns.  We’ve had people here locally that have had credit card information stolen.  We’ve had health records stolen. All this has happened here locally.”

Chandler says businesses need to become aware of cyber crimes, and learn how to protect their and their customers’ data.

“Doing a penetration type test, assessing your network, things of that nature. Those are all things that you should do at least once a year,” said Chandler. “Of course in a perfect world you would want to do it continuously.”

Padgett said he hopes all businesses will start to get serious about cyber crime and security.

“We depend on the people we give our information to to protect it,” said Padgett. “And we want those businesses to protect the information we give them.”

Chandler warned business owners that most insurance will not cover cyber crimes and their damage. He said owners need to increase their security, because cyber hackers are targeting companies here.

These kind of cyber security companies are some of the fastest growing in the industry because officials said hackers are targeting businesses of all sizes.

View the original content and more from this author here: http://ift.tt/1G4ppeD



from cyber security caucus http://ift.tt/1KDdk20
via IFTTT

The challenges of Cyber Security

We are living in a digital age, and that means the way we work, socialise and communicate has changed drastically. We now have to protect ourselves in ways that were unheard of 20 years ago, with the term “cyber security” instilling fear into the hearts of individuals business alike. However, one thing’s for sure; it is something that can no longer be ignored. So what are the key challenges and issues for businesses when it comes to cyber security?

Not just a jargon word

Sounds obvious, but it’s important to understand exactly what the term cybersecurity entails, and appreciate that it’s not just an empty jargon word. Cyber security is defined as “the protection of systems, networks and data in cyberspace.” It’s a critical issue for all businesses and will only become more important as more devices become connected to the internet.

Regulations

Most companies, especially those in the finance sector, spend a large chunk of their budgets on regulatory compliance. Yet because cybersecurity is a fairly new problem, regulations governing what companies need to do are yet to evolve. This inevitably poses challenges over what measures – if any – are appropriate to take.

Priorities

Companies – especially SMEs – don’t always see a need – or want – to invest a lot of money on cyber security measures when they could use that money for equipment and services that will directly increase profits. But is that a false economy? What would the impact be on their business if they were victim of a security breach? This risk needs to be considered against the investment required to safeguard a business.

Fast and furious

Cyber threats are incredibly difficult to foresee and can change too quickly for security experts to predict and find solutions. Staying one step ahead can be a time-consuming and expensive task.

A man (or woman) is only as good as their tools

After reviewing and tweaking security policies, companies need to figure out what new measures they need to take to beef up their security. This could be anything from regularly changing passwords, through to establishing sensors to send alerts when a communication network is compromised. Whatever it is, it is essential to use the appropriate tools for the job, and invest properly. A chain is only as strong as its weakest link, after all.

Risk management

It is common sense that a company should develop best practice guidelines, especially when it comes to collecting and handling sensitive data. But coming up with a fail-proof plan is easier said than done, and it often means modifying employees’ behaviour and adding to the number of tasks they have to perform. Education and communication is paramount; if a company’s staff are on board then a business is half way there.

Constant vigilance!

Given that cybersecurity breaches are unpredictable and could lead to disastrous consequences, businesses have to constantly evaluate and tweak their security policies. For smaller businesses in particular, managing this process can be time-consuming and onerous. Could outsourcing the task be more efficient?

Learn from your mistakes

A company must have policies and step-by-step guides that detail what happens after a security breach. No matter how minor it might seem, it is key to assess what went wrong, why it went wrong, and how to prevent it in the future.

Anything is better than nothing

Remember, just by reading this, at least your thinking about the threats posted by a security breach. Your IT vendor will be able to tell you more, and offer you a suite of products and services to get you started.

View the original content and more from this author here: http://ift.tt/1YCQT6G



from cyber security caucus http://ift.tt/1L7NTez
via IFTTT

The Forthcoming (?) China-U.S. Agreement on Cybersecurity

Press reports suggest that China and the United States are likely to come to an agreement to refrain from cyber actions that intentionally damage each others’ critical infrastructure.  It’s worth unpacking what such an agreement might entail, though of course speculation in the absence of specific language is always dangerous.

According to the New York Times, the United States and China are negotiating “a commitment by each country that it will not be the first to use cyberweapons to cripple the other’s critical infrastructure during peacetime.”  A provision of the June 2015 report of the Group of Governmental Experts (GGE) on Developments in the Field of Information and Telecommunications in the Context of International Security stated that in paragraph 13(f) that “A State should not conduct or knowingly support ICT activity contrary to its obligations under international law that intentionally damages critical infrastructure or otherwise impairs the use and operation of critical infrastructure to provide services to the public.”  Signed by representatives of 20 nations including the United States and China, this report asked member states of the United Nations to actively consider their recommendations that this and other norms of behavior.  Another press report indicated the United States and China would probably not address directly the point regarding critical infrastructure, but rather would announce a “generic embrace” of the GGE’s recommendations.

Several observations stand out to me.

  • This agreement would not address the major irritant in U.S.-China cyber relations today—that of cyber-enabled espionage regarding trade secrets and other intellectual property or regarding traditional intelligence gathering for military and/or foreign policy purposes.  This point, noted by a variety of press reports, is entirely true, and yet the agreement does try to address what is in fact a far more serious issue—the threat to critical infrastructure.  In the long run, maintaining the security of critical infrastructure is almost certainly an objective of higher priority than preventing cyber-enabled espionage.
  • The agreement would prohibit “intentional damage” to critical infrastructure but not intelligence-gathering activities involving critical infrastructure.  An interesting question then arises—how is one nation to distinguish between cyber activities conducted by the other nation that may on one hand be damaging or on the other hand for intelligence-gathering?
  • The agreement would be inherently unverifiable, or more precisely, as unverifiable as an agreement to refrain from using kinetic weapons to target ambulances on the battlefield.  This is not necessarily a reason for opposing the agreement—the United States is a party to certain agreements, such as the Geneva Conventions, that constrain its behavior without regard for whether another party’s compliance can be assured.  That is, we will not deliberately violate the laws of war even if other signatories to the Geneva Conventions do.  Regardless of the other side’s behavior, we find value in a commitment to observe the laws of war, and there may be similar value in this case.
  • An explicit embrace by Presidents Xi and Obama of the GGE 2015 recommendations would be both desirable and remarkable–desirable because it would be a step forward in improving cyber relations between the two nations, even if only symbolically, and remarkable in light of the lingering doubts about China’s commitment to the consensus achieved in the GGE.  I have been quite skeptical of that commitment, and I eagerly await tangible evidence that China is not seeking to back away from that putative agreement.

 

None of these comments negate Jack Goldsmith’s view that we shouldn’t get too excited about the reported agreement.  As Jack points out, the devil is in the details of how the two nations define the prohibited activities.  Jack’s comments regarding verification are also right on the money, and as an arms control agreement, what is being discussed falls far short of, for example, the Iran deal.  But even if that is true, and the forthcoming agreement merely represents better atmospherics, that’s better than a summit that breaks down because of mutual recriminations over the cyber issue.

View the original content and more from this author here: http://ift.tt/1KwdLxi



from cyber security caucus http://ift.tt/1KDdhU7
via IFTTT

Tech Report: Cybersecurity experts warn WiFi-enabled baby monitors are vulnerable to hackers

SAN LEANDRO (KRON) — Imagine being spied on in your own home.

Cybersecurity experts are warning that WiFi-enabled video baby monitors are being targeted by hackers. Tech reporter Gabe Slate met with a security firm to find out how you can protect yourself.

“Very scary, definitely feel violated,” said Jacqueline Arrizon, who is the mother of 2-year-old Phil.

Arrizon is reacting to the recent reports of video baby monitors being hacked to spy on children, and other dark deeds.

“You’re always kind of on edge with your kids,” she said. “You want to know where they are at and what they are doing. And to have somebody watching with you and not know that. It’s very scary”

“You won’t know,” Travis Moss of Safe Security said. “They won’t follow you around with the camera. They won’t talk through the mic. They are not going to alert you that they now have access to your network because they got other plans in mind for you.”

Travis, a cybersecurity expert, said there are peeping toms who will just watch you and listen to you through the baby monitors — and yeah — that’s creepy.

But the real danger is the hackers using the baby monitors as a gateway into your network and critical information.

“Any device that is WiFi enabled allows them into your network,” Moss said. “It’s like a Trojan Horse. They are going to use that to get to the real information, your identity and banking info etc..”

To protect yourself, make sure your home WiFi network has a strong password.

Change your user names and passwords often that are associated with your WiFi-enabled baby monitor. Make sure to run software updates for your baby monitor software or app.

View the original content and more from this author here: http://ift.tt/1G4poYk



from cyber security caucus http://ift.tt/1KDdhU3
via IFTTT

Wednesday, 23 September 2015

Leveraged Cybersecurity ETFs Are Debuting At A Dangerous Time

Summary

Direxion launched two leveraged cybersecurity ETFs this past week.

These ETFs may be debuting at a time when the popularity of cybersecurity stocks has already cooled and valuations are still very high.

History has taught us the dangers of investors choosing to chase past performance or chasing “hot” stocks.

It was probably just a matter of time before Direxion – one of the primary issuer of leveraged and inverse ETFs – jumped on the popularity of cybersecurity stocks. This past week, Direxion launched the Direxion Daily Cyber Security Bull 2X Shares ETF (NYSEARCA:HAKK) and the Direxion Daily Cyber Security Bear 2x Shares ETF (NYSEARCA:HAKD) options on the cybersecurity sector. But like many products that get launched after the initial popularity soars, the timing often proves to be a dangerous investor trap.

View the original content and more from this author here: http://ift.tt/1FdVoyd


from cyber security caucus http://ift.tt/1MIdaw5
via IFTTT