Monday, January 13, 2014

What Ender's Game Teaches About Information Security

I was reading Ender's Game to my son several months ago…probably my fifth time through the book. I came across a passage that really resonated with me. Ender is at Command School and he just got the crap kicked out of him by Mazer Rackham for no reason that Ender could discern.

Ender was angry now, and made no attempt to control or conceal it. "I've had too many teachers, how was I supposed to know you'd turn out to be a--"

“An enemy, Ender Wiggin,” whispered the old man. “I am your enemy, the first one you’ve ever had who was smarter than you. There is no teacher but the enemy. No one but the enemy will tell you what the enemy is going to do. No one but the enemy will ever teach you how to destroy and conquer. Only the enemy shows you where you are weak. Only the enemy tells you where he is strong. And the rules of the game are what you can do to him and what you can stop him from doing to you. I am your enemy from now on. From now on I am your teacher.”[1]



This is threat analysis - understanding your assets; understanding your enemy. Predicting what they going to go after and how they are going to do it. For intended, malicious threats, the adversary chooses his target assets and which attack methods he will use to compromise each asset – no one else. He chooses the battles that protectors of infrastructure will fight. He chooses the attack methods and, ultimately, he chooses the defenses that must be implemented to protect the infrastructure. Which enemies will attack your systems? Which of your systems will each enemy attack? What compromise methods will each enemy employ?

Securing an organization’s assets efficiently and effectively requires knowing the answers to these questions. Organizations that know the answers to these questions deploy the right controls to the right assets at the right time. They are flexible in their approach, changing their control structure to match the threat – adding new controls, enhancing existing controls, and scraping controls that no longer provide value. Every control in the environment provides a good return on investment. The security controls for each asset match the risk specific to each asset. They are ready when threats act upon them. Ultimately, their security risk profile is correct and the financial statements prove it.

Organizations that do not know the answers to these questions do not have the right controls deployed to the right assets at the right time. They are often in fire drill mode, reacting to successful attacks against themselves or to attacks that are pervasive among their peers. Their datacenter racks are littered with the blinking lights of security appliances that aren’t worth the power to run them. They are not ready when threats act upon them. Ultimately, their security risk profile is not correct and the financial statements prove it either due to money wasted on unnecessary controls or due to the costs of recovering from a compromise. Think TJ Maxx, Heartland Payment Systems, RBS WorldPay, and CardSystems Solutions.

Most of us operate somewhere in between these two extremes.  Regardless of where you are at on this continuum, the closer to correctly matching the threat for your environment and your assets is where you want to be. Knowing which enemies will attack your systems, which of your systems they will attack, and what compromise methods they will employ will help get you to a more efficient and effective risk posture.

Defend against attacks that will occur. Don’t defend against attacks that will never occur. Choose your battles wisely and fight them well.




[1] Orson Scott Card, Ender’s Game, pages 262-263, TOR Science Fiction

Saturday, January 11, 2014

Google Glass Day 5 - Glass Goes Skiing

Jacob and I ski at Park City every Saturday. Thought it would be a good chance to test out the Glass photo and video capabilities. Watch the video for results. I'm impressed. I liked the photo capabilities best. Didn't have to reach in for a phone. Nothing to drop on the lift. Just a 'wink' and the photo was taken.

The battery lasted about 3.5 hours under heavy photo and video use. I probably shot 25 minutes of video, 50 photos, and did 5 minutes of video play back. Not bad!

As far as skiing with Glass…probably won't do it again. The eye piece is too invasive. I need unrestricted vision when skiing. I suspect that Google will partner with optics manufacturers that will accommodate the Glass computing and optics modules. If they did that, I would use them for sports instead of my GoPro. Phone, compass, weather, camera, Strava all in one heads up display.


Friday, January 10, 2014

Cybercrime in the 2000s

Environment
Two technological innovations really changed the landscape of the Internet from something you ‘go on’ to something you are ‘always on’ – the iPhone and cloud computing. Prior to the release of the iPhone in 2007, getting on the Internet was ‘expensive’ in terms of time and location – you had to be at your desktop or your laptop and the system had to be connected to the Internet. Most often this was at work or at home, sometimes at a public access point.

The iPhone, and smart phones that followed, essentially put the Internet in the owner’s pocket on a very pleasantly usable device. Now you always had the Internet with you and didn’t have to go out of your way to use it. With this always on connectivity, individuals moved larger portions of their lives to Internet connected systems and, in doing so, moved larger swaths of their personal data to more systems – fitness activities, notes, photos, social, even their homes.

Cloud computing it made it easy for computing-intensive companies to set up shop. No longer was large capital investment required to build a computing-intensive company. With rates measured and charged in pennies per hour, companies could expand their computing infrastructure as needed. And they could do it easily, with much of the traditional heavy lifting of data center operations and networking already completed for them. The result has been an increase in Internet-based companies – SAAS providers and web startups.

Motives and Crimes
In the first decade of the millennium, the financial cybercrimes evolved from infrequent, one-man operations to frequent events perpetrated through a highly sophisticated, horizontally integrated criminal industry. Other criminal activities flourished too. While many of the crimes had been seen in previous decades, the frequency and magnitude of the crimes hadn’t.

Money – Bank Account Takeover
One of the biggest criminal developments of the 2000s was the formation of an entire industry devoted to compromising and pilfering online bank accounts. One of the earlier online account compromises occurred in June of 2005, when a fraudster gained unauthorized access to a Miami businessman’s online bank account using keystroke-logging malware and was able to fraudulently wire over $90,000 to an account in Latvia.[1] By the third quarter of 2009, fraudsters successfully hijacked hundreds of U.S. small business online accounts, hauling away over $25 million.[2]

This amount of criminal opportunity drove specialization, with some enterprises selling access to compromised systems, some selling custom malware, and others focusing on cashing out compromised accounts. A specific malware class of ‘banking trojans’ developed to enable bypass of online banking controls, such as Zeus, Sinowal, Carberp, SpyEye, and others. A fully featured license for Zeus, at one point, was selling in the criminal world for nearly $20,000.

Money - ATMs
ATMs are computer driven cash dispensers. If the account balance and daily withdraw limit line up with an authenticated request, then the machine will give the requested amount of money.  So, what happens when you steal a few cards and modify the account balances and daily withdraw limits? The WorldPay division of Royal Bank of Scotland found out.

On November 8, 2008, an army of cashers armed with compromised WorldPay pre-paid payroll cards descended on ATMs located in over 280 cities around the world and withdrew $9.5 million in cash in a twelve-hour period. The cashers kept their commission, 30-50% of the take, and wired the remainder to the scheme masterminds. The four leaders of the heist had previously broken in to the Royal Bank of Scotland WorldPay network and stolen data for 44 pre-paid payroll cards, cracked the payroll card PIN encryption, raised the funds available on each account up to as high as $500,000, and changed the daily ATM withdraw limit allowed. During the heist the hackers monitored the withdraw transactions remotely from the RBS WorldPay systems and, once the heist was finished, they attempted to cover their tracks on the RBS network.[3]

Money – Payment Card Theft
Grand scale payment card theft looks like Albert Gonzalez’s ‘Operation Get Rich or Die Tryin’, a payment card hacking crew that stole over 90 million payment card numbers from companies including Heartland Payment Systems, TJ Maxx, 7-Eleven, and Office Max and caused over $200 million in damages. Gonzalez and crew compromised the payment card processing systems at these companies by exploiting well-known vulnerabilities in their wireless networks and web applications. Upon arresting Gonzalez, agents found $1.6 million in his several bank accounts. His goal was $15 million, at which point he planned to buy a yacht and retire.[4]

Money – Identity Theft
Since 2001, identity theft has been the most common consumer complaint registered to the Federal Trade Commission. In 2012 16.6 million U.S. residents, ages 16 and older, were victims of identity theft. The vast majority of these thefts involved fraudulent use of an existing financial account, such as a bank account or credit card account.  The total cost of these crimes was estimated at $24.7 billion in 2012.[5]

Activism
Persons with a potentially more aggressive approach to activism took to the Internet in droves in the 2000s. One person’s 2010 New Year’s resolution was to actively disrupt sites he deemed to support “terrorists, sympathizers, fixers, facilitators, oppressive regimes and other general bad guys.” Operating under the handle ‘The Jester’, he frequently delivered on his resolution by launching Denial of Service attacks against sites he deemed to fit within in his objective.  His primary targets were wikileaks.org, for releasing the U.S. State Department cable messages, and sites or organizations he deemed to be aligned with terrorism.



Unknown numbers of people took up a variety of ‘hacktivist’ campaigns under the banner of Anonymous. Taking the opposite position as ‘The Jester’, Anonymous launched DDOS attacks against serveral financial firms in response to their ban of Wikileaks from their payment networks for publishing the U.S. State Department cables. A small Anonymous unit was involved in raising the awareness of the Stubenville High rape case.  Anonymous went after Sony to punish them for prosecuting George Hotz for successfully unlocking PlayStation 3 security system.

Ilmars Polkans campaign to expose fraud within the Latvian government was very effective and is worth researching. When filing his tax returns, Ilmars ‘unintentionally’ stumbled on a vulnerability on the Latvia Revenue Site that allowed him to see all tax filings. What he found was fat salaries for government officials during a time when citizens of Latvia, both public and private, were being forced to endure deep pay cuts because of the recession. His campaign to expose the injustice literally resulted in a public rebellion against the government.




[1] http://www.finextra.com/news/fullstory.aspx?newsitemid=13194
[2] http://krebsonsecurity.com/2010/03/cyber-crooks-leave-bank-robbers-in-the-dust/
Federal Indictment
http://www.justice.gov/opa/pr/2009/November/09-crm-1212.html
[4] http://www.wired.com/threatlevel/2010/03/tjx-sentencing
[5] http://www.bjs.gov/content/pub/pdf/vit12.pdf

Wednesday, January 8, 2014

Research Paper - The Rise of Cybercrime 1970s - 2010

I've finally completed my research on the rise of cybercrime. This paper  is a tour of the conditions that gave rise to cybercrime and the crimes themselves. I explain how we made the leap from petty phone access theft in the 1970s to multi-million dollar heists in the present day. In doing so, I visit the computing environment that shaped the crimes of each decade and I postulate the conditions that made all of this possible.

There are a lot of interesting crime stories in here - some well known, and some not so well known. And it is fun to just read about the computing environments of past decades. We shouldn't forget our roots!

I hope you find this to be fun and informative. Enjoy!

The Rise of Cybercrime - 1970 - 2010

Here are web links to sections of the paper in case you don't want to pull down the pdf…

The Conditions that Created the Perfect World of Cybercrime
Cybercrime in the 1970s
Cybercrime in the 1980s
Cybercrime in the 1990s
Cybercrime in the 2000s

Monday, January 6, 2014

Google Glass Day One Impressions

My Google Glass arrived today. First impression...they rock! I have rarely seen a product generate such awe as Google Glass did with the people I shared them with. Google, thank you for being cool enough to put out a technology early in the product development cycle rather than waiting for 'consumer perfection'.

Basically, I'm totally jazzed about the possibilities of Glass.  After the initial hour of exploration and play time, I couldn't help but think about the possibilities. I want a Glass-based WiFi security scanner app. I want a facial recognition app. I want location / context enrichment. I want a body language interpreter app. I want a…time to start digging in to the API.

Anyway, I fired them up with no instruction, except the brief navigation tutorial provided on the Glass. This got me to basic usage. I did quickly find that I needed to RTFM to understand how to fully navigate the UI.

Google must have some good optometrists on staff, because Glass is very comfortable and the screen works quire well. The user interface is good. The display appears to be projected a couple of feet in front of your eye. They don't try to cram too much on the display and the font is nice.

Navigation takes some getting used to. I'll be figuring that out over the next few days. My initial sense though is that they've done pretty well, both finger and voice based commands.

Inherently, I want Glass on the Internet all the time - like my cell phone. Unfortunately, tethering to your iPhone requires that you pay your phone company for 'personal hot spot' services - an extra $29.99 per month (not the case for an Android phone). No way. I'm already paying over $200 / month to those #%^$s. Fortunately, I was able to grab a MiFi mobile access point from work. So I'll be toting around Glass, cell phone, and MiFi.  Time to bust out the Batman utility belt.

Glass battery life on a full charge with what I would think is 'normal' use is about 4 hours.   Not bad. Could be better. I'm wondering if they will put out a dual battery model, with batteries on both sides to further increase battery life. I'm betting we'll see external battery pack add-ons.

From a data perspective, I can see why Google built these. Everything goes in to the Google cloud and is published through the Google+ platform. Google is going to know a lot more about the people who use these things. It is going to get pretty intimate…

Saturday, January 4, 2014

Cybercrime in the 1990s

Note: This is a section of the full research paper

Environment
By the end of the 1990s, the perfect conditions for cybercrime had formed: everyone was online, lots of people conducting online banking and credit card transactions, lack of legal framework and resources to prosecute cyber crime, and poor security. Two huge events in the 1990s made this happen. The first was the invention of the World Wide Web. In 1990, Tim Berners-Lee completed his build out of all the components necessary for his ‘WorldWideWeb’ project - a web server, a web browser, a web editor, and the first web pages. In 1991, he made his project publicly available on the Internet as the ‘Web’.  In a single decade, the Web grew from non-existent to over 17 million web sites. [1]

The other history-altering event was the build out of public internet access points. In 1994, the National Science Foundation sponsored four companies to build public Internet access points – Pacific Bell, WorldCom, Sprint, and Ameritech. Within a couple of years, Joe Public declared the Internet was good and got on-line.  At the beginning of the decade there were two million people on the Internet in the U.S. By the end of the decade there were 135 million.

Companies followed the public and moved their commerce channels online. The U.S. Department of Commerce reported for 1999 $5.25 billion in online travel bookings, $3.75 billion in online brokerage fees, and $15 billion in retail sales. Banks got on-line too, with 10 million people conducting banking online in 2000.

Adoption of the internet was not just a U.S. phenomenon. Though lagging developed economies by about five years, the emerging economies got online too. By 2000, 36 million people in the BRIC countries – Brazil, Russia, India, and China – were online. While the U.S. and its Allies established reasonably functional agreements for prosecuting cyber crime, no such agreements were realized with the rest of the world. The result was, and remains today, an internet with no functional legal system for fighting crime.

Motives and Crimes
With the millions of new systems coming online, the 1990s was a target rich decade for hackers.  Fortunately for businesses and people putting their private information online, hackers primarily made a sport of defacing websites, rather than targeting the sensitive information stored in the systems. It would take until the following decade for the criminal profiteers to figure out how to monetize computer crime.

Sport
The most common computer crime of the 1990s was defacing websites. Hacking for ‘sport’ is good category for these compromises. There really was no knowledge to gain, no curiosity to satisfy – just the sport of compromising web sites. Attrition.org documented many of the web site hacks through its web page hack mirror at http://attrition.org/mirror/. According to Attrition’s data, four web sites were hacked in 1995.  Attrition reported 1905 websites being hacked in 1999.



Number of Website Defacements Reported by Attrition.org[2]



Some very high profile sites fell during the decade. In 1996, the top sites compromised included the U.S. Air Force, NASA, and the site of the British Labour Party. Sites compromised in 1997 included Stanford University, Farmers & Merchants Bank, Fox News, and Yahoo.  Other high profile sites to be compromised included the U.S. Senate’s www.senate.gov, ebay.com, alashdot.org, and nytimes.com.

The content placed on these sites ranged from ‘Free Kevin!’, to pornography; from taunting messages like ‘Look you sorry ass system admin…’, to security advice such as ‘Stop using old versions of FTP’. A screenshot of part of the compromised senate.gov site is shown below.[3]



Money
There were a few notable money-driven computer crimes in the 1990s. In 1994, a group led by Vladimir Levin, broke in to the bank accounts of several corporations held at Citibank. Accessing the funds through Citi’s dial-up wire transfer service, he transferred $10.7 million to accounts controlled by accomplices in Finland, the United States, Germany, the Netherlands, and Israel.

In 1999, a Russian by the handle of ‘Maxus’ compromised the CD Universe web site and stole over 300,000 credit card records.  Attempting to profit from the crime, Maxus faxed an extortion note to CD Universe demanding $100,000 in return for silence of the theft and destruction of the stolen data. His extortion rejected, he published 25,000 of the records on a website. In reporting on the incident, ZDNET called it the ‘biggest hacking fraud ever’.[4]

Curiosity
Though the Melissa Virus wasn’t the first, it certainly opened the eyes of corporations and system administrators to the fragility and vulnerability of computer systems and the Internet. In 1999, David Smith, a network programmer, released the Melissa Virus to the Internet. The virus was contained in a Microsoft Word document macro. When an infected document was opened, it would email itself to the first 50 addresses in the MAPI email address file on the computer. In asking why he did it, David Smith stated that he just wanted to see if it would work.

It did work – splendidly, crashing an estimated 100,000 email servers. People readily opened the malicious document received from someone they knew containing a moderately convincing subject line and message. Besides, this type of attack was new. People weren’t used to being on their guard when opening up email attachments, especially from people they knew. 

Politics
A few political hacks occurred during the decade. In 1998, three members of the hacker group Milw0rm, as a protest of the Indian government’s nuclear weapons test program, broke in to several servers of the India Atomic Research Centre and modified the organizations homepage and stole thousands of emails and related research documents.[5] That same year hackers compromised and disabled filtering on a half-dozen firewalls used by China to filter its people’s Internet traffic.[6]




[1] http://www.cnn.com/2006/TECH/internet/11/01/100millionwebsites/
[2] http://www.phrack.org/issues.html?issue=55&id=18&mode=txt
[3] http://www.flashback.se/hack/1999/05/27/1/
[4] http://www.zdnet.com/biggest-hacking-fraud-ever-3002076252/
[5] http://www.wired.com/science/discoveries/news/1998/06/12717
[6] http://www.wired.com/politics/law/news/1998/12/16545

Wednesday, January 1, 2014

Cybercrime in the 1980s

Note: This is a section of the full research paper

Environment
In the 1980s the computer solidified its position in the upper income households, growing from over 1 million households with computers to in excess of 14 million by the end of the decade. In 1979, CompuServe introduced timesharing services to the public through a 100-baud service called ‘MicroNet’, with electronic mail as their first application. CompuServe added real-time messaging in 1980. By the end of 1981 they had 10,000 users. By 1987 it grew to 380,000. It was a bit pricey - $10 / hour. YouTube.com has an interesting vintage news report on the system (search ‘1981 primitive Internet report on KRON’).

Bulletin Board Systems continued to proliferate in the 80s. They didn’t have monthly access fees and were under the control of the person hosting the Board – not a corporation.  The Internet continued to remain the private domain of the government and some universities.

In the 1980s the cyber world, for all intents and purposes, was a geography-centric system, bounded within countries by telecommunications infrastructure borders and high international communications costs. Any cyber crimes that occurred within a country could be effectively investigated because the attack was likely staged within the same country and there just weren’t as many to investigate.

Motives and Crimes
Hacking in the 1980s was primarily about pursuit of knowledge, building reputations, a bit of politics, and games – games of breaking into systems and pulling off pranks. The hacker underground gathered and flourished in the anonymity and freedom of the Bulletin Board System where boards in the hundreds such as Hack-A-Trip, Hackers of America, Hi-Tech Pirates, Cult of the Dead Cow, Legion of Doom, PhoneLine Phantoms, and the Strata-Crackers formed. Through boards hackers shared their knowledge and displayed the trophies of their system exploits.

Curiosity / Reputation
Perhaps the most significant computer security event of the 1980s was the Morris Worm, a piece of computer malware written by Robert Morris, a graduate student at Cornell University. Though the only purpose of the worm was to propagate itself to other systems, it did degrade the performance of systems it compromised, causing significant impact to internet-connected systems it invaded.  It was estimated to

In 1988, Prophet of Legion of Doom compromised AIMSX, a BellSouth system. He did no damage, just explored. In his probing of the system he discovered a file containing information related to administration of the 911 system. Why did he download the file? It was a trophy – proof of his compromise of the system. Also, it was forbidden knowledge, and possession of forbidden knowledge was the currency with which reputation was purchased.[1]

Pranking
Some system compromises were simply to pull off a prank.  In June of 1989 a person compromised a Southern Bell phone switch and redirected calls made to the Palm Beach County Probation Department to “Tina,” a phone-sex worker in New York State.[2]

One of the earliest computer viruses was created as a joke. Elk Cloner, written by Rich Skrenta, spread to Apple II systems through infected floppy disks. The payload of the virus simply periodically displayed a humorous poem, in addition to replicating itself to any floppy disk inserted into an infected system.

Politics
The department of defense wasn’t left alone either. A Defense Data Network security bulletin was published on October 18, 1989, warning of a malicious worm attacking VMS systems on the SPAN network.[3]


 
Money
In 1989, a sixteen-year-old from Indiana gave an early glimpse of the future financially-motivated electronic crime wave to come two decades later. Fry Guy, so referred to in the computer underground because of his compromise of a McDonald’s mainframe, developed a knack for pilfering data from credit reporting agencies and for compromising phone-switching systems. Combining these two skills, he would phone Western Union and ask for a cash advance on a stolen card. To ensure the security of transactions, Western Union had a practice of calling the card owner back to verify the authenticity of the request. Having changed the card owner’s phone number temporarily to a public pay phone, Fry Guy would answer the phone as the cardholder and authorize the transaction.[4]




[1] The Hacker Crackdown page 112-113
[2] The Hacker Crackdown page 95
[3] http://www.textfiles.com/hacking/ddn03.hac
[4] The Hacker Crackdown page 100