Friday, September 2, 2011

Hackers, Mobile, Social Media Making IT Security a Challenge - Security - News & Reviews - eWeek.com - eWeek Mobile

http://mobile.eweek.com/c/a/Security/Hackers-Mobile-Social-Media-Making-IT-Security-A-Challenge-223185/

Mobile Security Trends

On 6/22/2011, my co-worker Jim Hewitt and I spoken and facilitated an
Executive Forum for HDI, a professional associations for IT support
The audience of this forum are CEO or CIO of fortune 500 companies and
some middle sized companies. I was impressed by the knowledge and
exhibited interest from this group of CXO.
We have talked about different mobile technology including 3G, 4G
(mostly Wimax and LTE), WiFi, NFC(Near Field Communication),
bluetooth, etc. We talked about the security trends on these mobile
technology, we also talked about the mobile app trends and associated
app security trends. The audience seemly had particular interest in
NFC and Mobile Device Management. From Strategic point of view, the
audience are also interested in defining the policy and process of
leveraging mobile device in the work place. Overall, it was a great 3
hour session discussion. The time pass by so quickly that we still
feel that there are lots of topics worthy further discussion in the
future. If you are interested in mobile security trends and would like
a copy of presentation slides, please leave me comment and I will send
you the slides.




My Great Web page




Global market for mobile security is expected to reach $14.4 billion by 2017

The tremendous popularity of mobile devices and their subsequent
appearance in the workplace means organizations have to worry about
data-stealing malware as well as the danger of lost and stolen
devices.

The increased risk to personal and corporate data is an opportunity
for the mobile-security industry, and the global market for mobile
security is expected to reach $14.4 billion by 2017, market research
firm Global Industry Analysts said in an Aug. 24 report. Issues such
as data breaches, unauthorized access to and loss of personal
information stored within the mobile phone, malware and malicious
applications all highlight the need for comprehensive mobile security.

The report, "Mobile Security: A Global Strategic Business Report,"
reviewed trends for all major geographic markets, including the United
States, Canada, Japan, Europe, the Asia-Pacific, Latin America and
others. Analysts also examined trends in mobile-security client
software and in mobile-network-security appliances and software, which
includes integrated security appliances, content security gateways and
intrusion-detection/-prevention systems.

"Security issues have taken on extreme importance in recent years,"
Global Industry Analysts said in the report.

The "evolution" of smart mobile computer devices such as laptops,
personal digital assistants, smartphones and tablet PCs into tools
commonly used for both business and personal use presents a
"tremendous opportunity" for the global mobile-security market, the
firm said.

Mobile-application development is a relatively new field, and
technologies for securing mobile-application code are immature,
analyst Chenxi Wang wrote in a recent Forrester Research report.
Vulnerabilities in mobile code, flawed application architecture or
improper handling of credentials can lead to embarrassing data
breaches, network intrusions or hacker attacks, Wang said.

Mobile-security client software is currently the fastest-growing
market as security vendors roll out mobile antivirus, Web-filtering
and other applications for smartphones and tablets. Global Industry
Analysts estimated that the market would grow by more than 53 percent
between 2008 and 2017.

Mobile devices have been transformed into "a multi-faceted
multi-tasking, multimedia device," delivering tools for personal
expression, enterprise computing and entertainment, the firm said.
Mobile devices are now used for video conferencing, storing documents
and media, sending and receiving email messages, online banking and
shopping and other entertainment purposes.

While the productivity benefits are "undeniable," the new capabilities
and features "open up new apertures for risks," according to Global
Industry Analysts. The threat of malicious applications compromising
the mobile device and accessing key information stored within poses
significant risks to the organization and is "a perfect business case
for mobile security."

The biggest gains in mobile security will be in the Asia-Pacific
region, driven primarily by "robust demand" for mobile devices in
emerging countries, such as China and India, according to Global
Industry Analysts.

Mobile networks are also experiencing "exploding data traffic" as a
direct result of the "exponential rise" in the number of
Internet-connected mobile devices, the company said. Customer demand
has also forced mobile-network operators to stop restricting users to
a set of default services provided by the carrier and instead give
them access to all services and content on the World Wide Web. Mobile
operators have to balance the seamless integration of proprietary
networks and the entire Internet with security and privacy concerns
that inevitably would arise, according to the analysts.

"Mobile-network providers will therefore come under increased pressure
to invest in mobile-security appliances and software to protect both
their networks as well as network users," the analysts wrote.

Source: http://mobile.eweek.com/c/a/Security/Global-Mobile-Security-Market-Worth-144-Billion-in-2017-Report-212602/

Identity thieves increasingly target children

A recent investigation into illegal immigrants who were hired by a
Texas nursing home after they bought Social Security cards revealed
that seven of the identification numbers on the fake cards belonged to
children, a Social Security Administration special agent said
Thursday. Increasingly, identity thieves are hacking computers at
schools and pediatric centers to retrieve this lucrative personal
information, experts say.

"While this investigation involved a very small sample, we found that
of 28 misused SSNs identified, 25 percent belonged to children,"
Antonio Puente, special agent for the SSA Office of Inspector
General's Dallas field division, testified at an off-site
congressional hearing. The House Ways and Means Subcommittee on Social
Security held the session in Plano, Texas, to examine the growing
problem of child identity theft.

More than 140,000 American children each year become victims of
identity theft, experts said at a July child-centric fraud forum
sponsored by the Federal Trade Commission. That number includes kids
whose relatives, when in a financial bind, applied for new credit with
their young family member's name and Social Security number. Reports
of child identity theft increased nearly 200 percent between 2003 and
2009, when 19,000 cases were filed, according to FTC figures.

Robert Feldt, special agent in-charge at the same Texas division, said
child identity theft "allows for the potential long-term undetected
abuse of a genuine SSN -- and the potential long-term harm to a young
person's financial future." It usually isn't until about 18 years
later that the adult victim discovers a mysterious history of unpaid
bills or loan defaults.

All the suspects questioned during the nursing home incident were
Mexican nationals who currently are undergoing deportation and removal
proceedings, Puente said.

In one new form of identity fraud, corrupt vendors use dormant Social
Security numbers, particularly those assigned to children, to
establish bogus credit files for people with bad credit, Feldt said.
They advertise these offerings, called credit profile numbers or
credit protection numbers, on websites at prices between $40 and
$3,500.

"Despite what many of these credit repair websites imply, consumers
should know that CPNs are not legal," he testified.

The inspector general's office is pushing for legislation that would
limit the ability of local governments and companies to access and
display Social Security Numbers. Schools and social services agencies
often widely circulate sensitive personal data for kids in foster
care, leaving foster children especially vulnerable to identity theft,
panelists at the July summit said.

Source: http://www.nextgov.com/nextgov/ng_20110901_8644.php?oref=rss?zone=NGtoday

Sunday, August 28, 2011

Denial of Service Attack on Apache Server can become imminent


According to the recent article on Fast Company entitled "Apache Killer Is The Biggest Little Internet Threat" by Kit Easto, there is a vulnerability in the latest version (as of 8/28/2011) of Apache Server which is susceptible for DoS attack. 

According to Kit Easto, The vulnerability goes like this:

"When your browser asks for website code from an Apache server, the system listens to the request, then sends the relevant HTML files off to you. But your computer can also, of course, download other files from a web server--and as part of the complicated digital chat that goes on between your PC and the Apache server there's a variable named "range" that gets sent from your PC to the server. It basically says "if the file I'm asking for is really big, say a gigabyte, then please break it up into smaller chunks." Apache Killer is a simple code that pings a server, and basically says to the server to break up even a small file into a vast number of tiny chunks, using this "range" variable. The server tries to comply with the request, but it's technically impossible...and so it runs out of memory swiftly, or encounters any number of other errors, and then will typically crash. Taking the server offline, along with any websites it's hosting."

Tuesday, June 7, 2011

Will iCloud be the next target for hackers?

With Apple's announcement of iCloud at WWDC on Monday, the migration
of data and assets to the cloud space seems to be accelerating and
irreversible.
iCloud's massive online storage system allows users to access their
data from any decive connected to the Internet. You can access your
music library, documents, photos, and all contents from any iOS
device, from anywhere. In an era where everyone juggles multiple
devices, iCloud answers the hassles of keeping all your devices in
sync.

With recent security breaches in RSA, Sony, L3 and other big name companies, can AAPL be the next target?

Personally, I believe that AAPL should leverage two factor authentication and encrypt data with FIPS 140-2 Approved algorithm.  At this point, only apple ID is used for the authentication. This could be a brute force target for the hackers.

Also, AAPL should evaluate a good Identity and Access Management solution to provision the user and provide attribute based and fine grained access control. With the cash from its line of business, it is not too late for AAPL make good investment in the cloud security before AAPL become the front page of Washington Post due to security problems.

iCloud Paves Way to Glory Days in China - Paul Denlinger - China At The Crossroads - Forbes

iCloud will be a successful story in China

Please see the following article

http://blogs.forbes.com/pauldenlinger/2011/06/06/icloud-paves-way-to-glory-days-in-china/?partner=asia_newsletter