Monday, 2 November 2015

ICIT Brief: Know Your Enemies – A Primer on Advanced Persistent Threat Groups

Every system connected to the internet in every home, organization, and government entity is relentlessly subject to the attempts of malicious actors to steal their data or exploit their system. Cyber-attacks are prevalent in the digital age because computers (including mobile devices) are ubiquitous in society, because identification of an attacker and attribution is difficult, and because judicial rulings for cyber-crimes are nebulous.  Most cyber-attacks are prevented by basic security measures such as firewalls and antivirus applications. However, an elite percentile of the sea of cyber attackers is more persistent, more resourceful, and more sophisticated than the rest. These elite factions are known as Advanced Persistent Threats, and basic security measures are not enough to stop them from compromising some of the best-secured systems around the world.

In our latest brief, entitled “Know your Enemies:  A Primer on Advanced Persistent Threats“, the Institute for Critical Infrastructure Technology (ICIT) pulls back the veil  on the world’s most prominent threat actors to assist the reader in better understanding its adversaries from countries including Russia, China, Iran, and North Korea.  This primer provides an overview of the threat landscape, attack vectors, size and sophistication of threat actors.  Some of the Groups and Platforms include: The Elderwood Platform, Topsec, Axiom, Hidden Lynx, Deep Panda, PLA Unit 61398, Putter Panda, Tarh Andishan, Ajax, Bureau 121, Energetic Bear, Uroburos, APT 28, Hammertoss, CrazyDuke, Sandworm, Syrian Electronic Army, Anonymous and Butterfly Group among others.

This brief was written by ICIT Sr. Fellow James Scott and ICIT visiting scholar Drew Spaniel from Carnegie Mellon University.

Click HERE to download this brief.



from cyber security caucus http://ift.tt/1Md7cBZ
via IFTTT

Cybersecurity ETFs Launch

Computerized security breaches are now a regular part of the daily news. From an investment angle, electronic attacks have been a boon to cybersecurity stocks, which are receiving new business as companies spend money to defend themselves against cyber-attacks.

Direxion Investments launched the Cyber Security Bull and Bear 2X Shares (HAKK/HAKD) targeting this emerging industry sector. Both funds are linked to the ISE Cyber Security Index and aim for 200% daily and 200% daily opposite (inverse) exposure.

“Our new leveraged ETFs enable traders to benefit from exposure to these industries, regardless of market conditions and sector performance, in a flexible way,” said Sylvia Jablonski, managing director at Direxion. For the full article click here



from cyber security caucus http://ift.tt/1Ro9GNR
via IFTTT

New hub to fight cybercrime opens

A NEW cybersecurity hub was unveiled in Pretoria on Friday, with Telecommunications and Postal Services Minister Siyabonga Cwele saying SA — currently among the world’s major cybercrime hotspots — can beat cyberattacks and disruptions.

The virtual hub has been established to serve as a central point for collaboration between industry, the government and civil society on all cybersecurity-related incidents in SA.

Information gathered through the hub will be used to monitor cyberattacks and provide warnings to stakeholders of immerging threats. It will serve as an information centre for solutions on how to deal with threats and enable stakeholders to get updates on preemptive measures to strengthen their systems against cyberattacks.

“We need to mobilise our resources to train and equip our cybersoldiers with high-end skills and technology to defend our nation,” he said.

The launch of the hub comes as financial experts warn that a lack of knowledge of new financial technologies, coupled with the absence of global regulation, are putting consumers at higher risk of falling victim to cybercrime.

The future will increasingly feature more online and mobile technologies with sophisticated apps and services, while customers on the other hand, would not necessarily be more sophisticated or literate financially. This could place them at more risk of cybercrime.

Results from a study by marketing research company Columinate revealed that SA is the third highest cybercrime hotspot in the world, with 50% of credit card fraud happening online. For the full article click here



from cyber security caucus http://ift.tt/20mS5Mq
via IFTTT

2 degrees, flies planes, author, works at NASA. His age? 17

Moshe Kai Cavalin has two college degrees, but he’s too young to vote. He flies airplanes, but he’s too young to drive a car alone.

Life is filled with contrasts for Cavalin, a 17-year-old from San Gabriel, California, who has dashed by major milestones as his age seems to lag behind. He graduated from community college at age 11. Four years later, he had a bachelor’s in math from the University of California, Los Angeles.

This year, he started online classes to get a master’s in cybersecurity through the Boston area’s Brandeis University. He decided to postpone that pursuit for a couple of terms, though, while he helps NASA develop surveillance technology for airplanes and drones.

Between all that, he’s racked up an exhausting list of extracurricular feats. He just published his second book, drawing on his experience being bullied and stories he’s heard from others. He plans to have his airplane pilot’s license by the year’s end. At his family’s home near Los Angeles, he has a trove of trophies from martial arts tournaments.

Still, Cavalin insists that he’s more ordinary than people think. He credits his parents for years of focused instruction balanced by the freedom to pick his after-school activities. His eclectic interests stem from his cultural heritage, he said, with a mother from Taiwan and a father from Brazil. For the full article click here



from cyber security caucus http://ift.tt/20mS5Mi
via IFTTT

Senate Passes NRECA-Backed Cyber Bill

The Senate approved S. 754, “Cybersecurity Information Sharing Act of 2015,” in a 74-21 vote Oct. 27 after rejecting several amendments that would have complicated and delayed critical information sharing or eliminated protections for voluntary exchanges to shore up cybersecurity.

“This step forward for our national cybersecurity will enhance and encourage communication among the federal government, the North American electric power sector, and other critical sectors that will improve cooperatives’ abilities to defend against or mitigate a cyber event,” said Bridgette Bourge, NRECA senior principal.

“This bill will help electric co-ops advance their awareness of cyber threats and enhance their protection and response capabilities through improved and protected information sharing through existing channels.”

For the full article click here



from cyber security caucus http://ift.tt/1k3UDhY
via IFTTT

Saturday, 31 October 2015

ICIT Chastises OPM’s Lack of Modern Cybersecurity in an Official Analysis

The Institute for Critical Infrastructure Technology (ICIT) describes itself as a “nonprofit (status pending), non-partisan group of the world’s most innovative experts and companies that provide technologies and solutions to support and protect our nation’s critical infrastructures.” ICIT serves as a go-between for the private sector, federal agencies, and the legislative community in key areas such as Cybersecurity, Big Data, and Health IT. It is in the scope of Cybersecurity that ICIT performed a recent analysis on the OPM (Office of Personnel Management) Breach which began in March 2014 and was publicly announced in June of 2015.

This official analysis, “Handing Over the Keys to the Castle: OPM Demonstrates that Antiquated Security Practices Harm National Security,” details the most important aspects of the breach. Some of these aspects have not been discussed in the mainstream media including:

For the full article click here



from cyber security caucus http://ift.tt/1jZqWP9
via IFTTT

IEEE’s Shannon Appointed White House Cybersecurity AD

Greg Shannon, an IEEE senior member and cybersecurity expert from Carnegie Mellon University (CMU), recently began an assignment in the White House Office of Science and Technology Policy (OSTP) as assistant director for cybersecurity strategy in the National Security and International Affairs Division.

IEEE-USA provided a fellowship to CMU to partially support faculty or staff who have the opportunity to serve temporarily in the Executive Office of the President.

Since 2010, Shannon has been chief scientist for the CERT Division at CMU’s Software Engineering Institute (SEI). The division is dedicated to improving the security and resilience of computer systems and networks, especially for national security, homeland defense and critical infrastructure.

As chief scientist, Shannon led the division to advance the science of cybersecurity with new research capabilities for the Defense Advanced Research Projects Agency (DARPA), the Intelligence Advanced Research Projects Agency (IARPA) and the Department of Homeland Security. For the full article click here



from cyber security caucus http://ift.tt/1LIdDLT
via IFTTT