Home Podcasts Videos Guest Posts Q&A My Take Bio Contact
 

My Take

 

MY TAKE: The no. 1 reason ransomware attacks persist: companies overlook ‘unstructured data’

By Byron V. Acohido

All too many companies lack a full appreciation of how vital it has become to proactively manage and keep secure “unstructured data.”

One reason for the enduring waves of ransomware is that unstructured data is easy for hackers to locate and simple for them to encrypt.

Related video: Why it’s high time to protect unstructured data

Ironically, many victimized companies are paying hefty ransoms to decrypt unstructured data that may not be all that sensitive or mission critical.

I talked with Jonathan Sander, Chief Technology Officer with STEALTHbits Technologies, about this at Black Hat USA 2018.

The New Jersey-based software company is focused on protecting an organization’s sensitive data and the credentials attackers use to steal that data. For a drill down on our conversation about unstructured data exposures please listen to the accompanying podcast. A few takeaways:

Outside a database

Structured data can be human- or machine-generated, and is easily searchable information usually stored in a database, including names, Social Security numbers, phone numbers, ZIP codes.

Unstructured data (also human- or machine-generated) is basically everything else. Typical unstructured data includes a long list of files—emails, Word docs, social media, text files, job applications, text messages, digital photos, audio and visual files, spreadsheets, presentations, digital surveillance, traffic and weather data, and more. In a typical day, individuals and businesses create and share a tidal wave of this information.

The main difference between the two is organization and analysis. Most of the unstructured data generated in the course of conducting digital commerce doesn’t get stored in a database or any other formal management system.

For structured data, users can run simple analysis tools, i.e., content searches, to find what they need. But with no orderly internal framework, unstructured data defies data mining tools. Most human communication is via unstructured data; it’s messy and doesn’t fit into analytical algorithms.

Ransomware target

There is a mountain of unstructured data compared to a molehill of its structured counterpart. Gartner analysts estimate that over 80 percent of enterprise data is unstructured …more

MY TAKE: Poorly protected local government networks cast shadow on midterm elections

By Byron V. Acohido

In March 2018, the city of Atlanta fell victim to a ransomware attack that shut down its computer network. City agencies were unable to collect payment. Police departments had to handwrite reports. Years of data disappeared.

Related: Political propaganda escalates in U.S.

The attack also brought cybersecurity to the local level. It’s easy to think of it as a problem the federal government must address or something that enterprises deal with, but cybersecurity has to be addressed closer to home, as well.

I spoke to A.N. Ananth, CEO of EventTracker, a Netsurion company, about this at Black Hat USA 2018. His company supplies a co-managed SIEM service to mid-sized and large enterprises, including local government agencies.

EventTracker has a bird’s eye view; its unified security information and event management (SIEM) platform includes – behavior analytics, threat detection and response, honeynet deception, intrusion detection and vulnerability assessment – all of which are coupled with their SOC for a co-managed solution. For a drill down on our discussion, give the accompanying podcast a listen. Here are key takeaways:

Local risks

Security of local and state government agencies takes on a higher level of urgency as we get closer to the midterm elections.

“State and local governments are not immune to the digital transformation so their dependence on IT is as high as it’s ever been,” says Ananth. “Consequently, the security of these kinds of systems has become paramount.”

If all politics are local, elections are even more so. According to the National Conference of State Legislatures, security for elections is in the hands of local election administrators, overseen by the state’s chief election official, but protection has been lacking.

During 2016, 39 states were hacked. At least one state saw an attempt to delete voter rolls; …more

MY TAKE: Here’s how diversity can strengthen cybersecurity — at many levels

By Byron V. Acohido

Of the many cybersecurity executives I’ve interviewed, Keenan Skelly’s career path may be the most distinctive. Skelly started out as a U.S. Army Explosive Ordnance Disposal (EOD) Technician. “I was on the EOD team that was actually assigned to the White House during 9/11, so I got to see our national response framework from a very high level,” she says.

Today, Skelly is Vice President of Global Partnerships and Security Evangelist at Circadence®, a distinctive security vendor, in its own right.

Related: How ‘gamification’ makes training stick

Circadence got started in the 1990s as a publisher of one of the earliest massively multiplayer online games. It adapted its gaming systems to help the U.S. military carry out training exercises for real life cyber warfare. That led to a transition into what it is today: a leading supplier of immersive “gamification” training modules designed to keep cyber protection teams in government, military, and corporate entities on their toes.

I met with Skelly at Black Hat USA 2018 and we had a thoughtful discussion about a couple of prominent cybersecurity training issues: bringing diversity into AI systems and closing the cybersecurity skills gap. For a drill down, please listen to the accompanying podcast. Here are key takeaways:

Diversifying AI

Discussions are underway in the technology sector about how Artificial Intelligence could someday eliminate bias in the workplace, and thus engender a more meritocratic workplace

“We’re starting to see Artificial Intelligence and machine learning in just about every space and every tool,” Skelly observes.

Diversity in emerging AI-infused security systems – or, more specifically, the lack of it – is a rising concern. Here’s why: The experts with the knowledge to tweak the algorithms for automated detection systems, at this moment, comprise a very narrow talent pool. The concern is that this could constrain the development of broadly effective security-focused AI.

“The problem is that if you don’t have a diverse group of people training the Artificial Intelligence, …more

MY TAKE: Can Hollywood’s highly effective ‘source-code’ security tools help make IoT safe?

By Byron V. Acohido

Over the past couple of decades, some amazing advances in locking down software code have quietly unfolded in, of all places, Hollywood.

Related: HBO hack spurs cyber insurance market

Makes sense, though. Digital media and entertainment giants like Netflix, Amazon, Hulu, HBO, ESPN, Sony, and Disney are obsessive about protecting their turf. These Tinsel Town powerhouses retain armies of investigators and lawyers engaged in a never-ending war to keep piracy and subscription fraud in check.

And over the years they’ve also financed security breakthroughs – at the source-code level. These security breakthroughs have not received much mainstream attention. What they have done is proven to be wickedly effective at tracking digital assets and preserving digital rights.

I recently had the chance to meet with Mark Hearn and John O’Connor, of Irdeto, a 50-year-old software security and media technology company based in Amsterdam that has been a leading supplier of source code tracking and fingerprinting systems for big media companies.

We met at Black Hat USA 2018, where Hearn and O’Connor, came bearing a message about how these technologies, so heavily relied on by Hollywood, could play a starring role in shoring up the foundational  layers of digital transformation — at the source code level.

For a drill down on our discussion please listen to the accompanying podcast. Here are the big takeaways:

Making it too expensive

Irdeto’s suite of products helps set-top box manufacturers protect high-value content; its technology also is used by live sports broadcasters to deter hackers from siphoning off pay-for-view sporting events.

Irdeto’s Cloakware technology is a key component in these technologies. …more

MY TAKE: The amazing ways hackers manipulate ‘runtime’ to disguise deep network breaches

By Byron V. Acohido

There is a concept in computing, called runtime, that is so essential and occurs so ubiquitously that it has long been taken for granted.

Now cyber criminals have begun to leverage this heretofore innocuous component of computing to insinuate themselves deep inside of company networks.

Related: The coming wave of ‘microcode’ attacks

They’ve figured out how to manipulate applications while in runtime and execute powerful and stealthy attacks that bypass conventional security tools.

This is a big leap forward for elite threat actors, who have long targeted static files, storage, and executable code, either at rest on disk or in transit. What they’re doing is intricately technical. But it’s happening on an increasing basis in the Internet wild  to exploit vulnerabilities, spread ransomware, steal valuable data and to usurp control of industrial plants.

I asked Willy Leichter, vice president of marketing at Virsec, a supplier of data security systems, to dissect how runtime is essentially being weaponized to support advanced network compromises. We met at Black Hat USA 2018. For a full drill down, please listen to the accompanying podcast of our conversation. Here are key takeaways:

Runtime defined

Runtime refers to the period of time between opening a software program and quitting, or closing, it.  During runtime, pieces of the application get loaded into the RAM (random access memory) of the computing device’s CPU (central processing unit) allowing the app to do its thing.

Runtime occurs continually in our digital world. It comes into play any time software applications get executed “on premises” in a company network and across any mobile app or cloud-delivered service. This includes when you use email, a productivity tool, a mobile app, social media, or an Internet of Things device.

Here’s the rub: threat actors have discovered how to slip benign-looking snippets of data into application servers, that then get transformed into malicious code during runtime. …more

MY TAKE: Can ‘Network Traffic Analysis’ cure the security ills of digital transformation?

By Byron V. Acohido

If digital transformation, or DX, is to reach its full potential, there must be a security breakthrough that goes beyond legacy defenses to address the myriad new ways threat actors can insinuate themselves into complex digital systems.

Network traffic analytics, or NTA, just may be that pivotal step forward. NTA refers to using advanced data mining and security analytics techniques to detect and investigate malicious activity in traffic moving between each device and on every critical system in a company network.

Related: How the Uber hack pivoted off of DevOps

A cottage industry of tech security vendors is fully behind NTA. I recently visited with Jesse Rothstein, co-founder and Chief Technology Officer of ExtraHop, a leading NTA vendor.

It was one of the more fascinating conversations I had on the floor at Black Hat USA 2018. For a full drill down, please listen to the accompanying podcast. Meanwhile, here are key takeaways:

Data ingestion advances

Traditionally, security analytics has revolved around assessing flow data and log data – a record of the movement of data between systems and shorthand notes about activity on a system. SIEM-based detection systems and earlier network-focused security products developed along these lines.

This unfolded, in part, because capturing and storing much richer data sets really wasn’t feasible 10 years ago, Rothstein told me. Then along came advances in data ingestion and processing, or obtaining and preparing data for immediate use.

Advanced data ingestion techniques made it possible to move beyond just monitoring flow data; …more

What companies need to know about ‘SecOps’ — the path to making ‘digital transformation’ secure

By Byron V. Acohido

DevOps has been around for a while now, accelerating the creation of leading edge business applications by blending the development side with the operations side.

It should come as no surprise that security is being formally added to DevOps, resulting in an emphasis on a process being referred to as SecOps or DevSecOps.

Related: How DevOps played into the Uber hack

It’s a logical transition. With DevOps, the two teams merged together to purse a common goal  – to drive value for the organization. To do that, the teams are finding better ways to work together and break down barriers.

With the digital transformation really just beginning, in cloud computing and IoT, it makes sense to bring security into the DevOps conversation. The security team needs to be at the table, working alongside the developers and the operations teams, providing the risk management view for security.

Oil and water

I visited with Dan Cornell at Black Hat USA 2018. Cornell is the chief technology officer at the application security firm Denim Group. We discussed the general guidance Denim Group offers its clients and how its ThreadFix vulnerability management platform is helping organizations bridge the gap between DevOps – whose aim is to deliver innovative applications with great flexibility at high velocity – and the security side of the house.

Yes, it’s like blending oil and water. However, the full fruition of DevSecOps is something that is going to have to happen if digital transformation is to achieve its full potential. …more