Friday, March 13, 2015

Security Updates for the week of March 13, 2015



Watch Out For A New Ransonware Variant!


Trend Micro has reported on several variants of both ransomware and crypto-ransomware, each with their own “unique” routines.  A new variant is called PE_VIRLOCK that not only locks the computer screen but also infects files—a first for ransomware.  Unlike other ransomware, it appears to have self-propagation abilities.

There is significant chance of executing VIRLOCK on removable drives by mistake since the icons used by infected files are the same as what you’d expect for certain files on a flash drive. The infected files on the affected removable drive can infect computers with ease.

VIRLOCK variants may arrive bundled with other malware in infected computers.

Once inside the computer, VIRLOCK creates and modifies registry entries to avoid detection and ensure execution.  It then locks the screen of the affected computer, disabling explorer.exe and preventing the use of taskmgr.exe. Meanwhile, it also checks the location of the affected system to display the appropriate image for the ransom message.

If the infected system is not properly cleaned, even the presence of a single infected file will trigger the infection chain all over again. Once VIRLOCK gets into a system network, it will be all over the place; it can infect a whole network system without notice.

As VIRLOCK has propagating capabilities, users are encouraged to limit connecting their removable drives to computers that are trusted or with security software installed. The same goes for computers: avoid connecting flash drives that cannot be vouched by other people.
Check with your current anti-virus/anti-malware provider for the best removal techniques for your particular system(s).

CAPTCHA Security Can Now Be Fooled By Hackers  
We’ve all been frustrated by security gateways that require us to visibly inspect a graphic of distorted letters and numbers and type in what we see to get past a security check.  Now hackers have found a way around that too.  The Russia-based anti-virus company Kaspersky Labs revealed on Wednesday that the malware, Trojan-SMS.Android.Podec, is now capable of circumvented CAPTCHA image security.
The Podec malware automatically forwards CAPTCHA requests to a real-time online human translation service, Antigate.com, which converts the image to text, and relays that data back to the malware code within seconds, convincing the verification system that it is a person. The purpose of the Trojan is to extort money from victims by subscribing thousands of infected Android users to premium-rate services, said the security software company.  Watch your credit card bills for bogus charges!

Beware of Apple Watch Phishing e-mails

Malwarebytes reports that hackers have jumped on the unveiling of the Apple Watch as a chance to phish for data through social networks.  Victims are reportedly lured into the scam through the promise of a free Apple Watch, but instead are redirected onto a series of bogus links in what appears to be a phishing exercise to collect people's details.
 

Panda Anti-Virus says OOPS!

Panda users had a bad day on Wednesday, after the Spanish security software firm released an update that classified components of its own technology as malware.   As a result, enterprise PCs running the antivirus software struggled to function and leaving some systems either unstable or unable to access the internet. A Panda spokesman confirmed the problem while advising that the issue was well in hand.
A company official advisory about the problem says that the issue was limited to Panda Cloud Office Protection, Retail 2015 products and Panda Free AV. Users are strongly advised not to restart their computer until a fix is available.

New Facebook Exploit Delivers Malware Worm

The folks at MalwareBytes came across a worm whose purpose is to compromise a user and spread via Facebook.  The lure is the promise of pornographic material that comes as what appears to be a video file named Videos_New.mp4_2942281629029.exe, which in reality is a malicious program.

Once infected, the victim spreads the worm to all of his contacts and groups that he belongs to, by posting the following message:
Sex photos of teen girls in school – NEW SCANDAL  Like · · Share

The bad guys have built a multi-layer redirection methodology that uses the ow.ly URL shortener, Amazon Web Services and Box.com cloud storage.  Once again these hackers are leveraging human nature and while it’s difficult to know how many people fell for this threat, we can guess that it most likely affected a significant number of Facebook users.

Are Your Microsoft Patches Up-To-Date

With the latest Patch Tuesday release, Microsoft fixed the latest FREAK vulnerability that could help attackers intercept secured network communications.  The security bulletin is one of 14 Microsoft issued Tuesday, five of which are marked critical, meaning administrators should apply them as quickly as possible. 

The updates address vulnerabilities in both the consumer and server editions of Windows, Internet Explorer, Office, SharePoint Server and Exchange Server.


Need help with your network security?  Call Jeff Hoffman @ ACT Network Solutions or e-mail him at jhoffman@act4networks.com




Friday, March 6, 2015

Here’s your ACT Security Updates for the week of March 6, 2015

Secure Web Site Communication Compromised by the FREAK SSL/TLS vulnerability
A scan of more than 14 million websites that support the SSL/TLS protocols (sites using HTTPS: ) found that more than 36% of them were vulnerable to these “Freak” decryption attacks.
Essentially, an infected web site using certain versions of SSL can be manipulated to downgrade the high level encryption keys to a more easily exploited version and after discerning the keys, the hacker can figure out how to “see” all communication in plain text and then manipulate the communication to their advantage.

If you’d like to see a list of reported hacked websites by Freak click here.  https://freakattack.com/

Google said an Android patch has already been distributed to partners.
Apple also responded to the FREAK vulnerability and released a statement that, "We have a fix in iOS and OS X that will be available in software updates next week."  Microsoft is publishing an update as well.


Midlothian Police Dept. pays Cryptoware Ransom to get their data back

Recently, the police department of Midlothian, Illinois paid a ransom of over $600 in Bitcoins to an unknown hacker after being hit by the popular ransomware attack. 
Cryptoware disabled a police computer in Midlothian — located south of Chicago — by making it inaccessible through its file-encryption capabilities and forced the police department to pay a ransom in order to restore access to the important police records proving that it can happen to anyone!

Ticked-off Hackers Exact Their Revenge on Lenovo for Superfish Vulnerability

Users visiting the Lenovo.com website saw a teenager's slideshow of photos and the hacker also added the song "Breaking Free" from High School Musical movie to the website page background. 

It was revealed last week that Lenovo had been pre-installing the controversial 'Superfish' adware to its laptops which compromised the computer's encryption certificates to quietly include more ads on Google search.  It appears that the Lizard Squad hacking group is responsible for the cyber-attack against Lenovo and it could be in retaliation to the Superfish malware incident.

 And speaking of the Lizard Squad  . . .
Forbes Magazine reported today that hacking suspects in the DoD and Yahoo attacks and an alleged Lizard Squad Member were arrested by police in the UK.  As many as 56 individuals were arrested over the last week, as part of a crackdown led by London-based National Crime Agency (NCA) on a range of cybercrimes.
 Are Your Web Tools Up-To-Date?
If you pay attention to hacking and exploit news, you’ll see 3 apps or modules pop up time after time.  It’s very important that you keep all of your utilities and apps updated but these 3 are the most commonly exploited because they are used on almost every computing device out there.  Here are the current versions for each of them.  If you’re not using these versions, you should consider running updates for them.
The one qualifier I would add before you do that is – make sure that you’re not running a program or web app that requires an older version and might not support the upgraded release.  If you have such a situation, you may want to impress upon that vendor the need to upgrade their software to meet current standards.

Javascript  -                        version 1.8.5
Adobe Acrobat Reader - version XI (11.0.10)
Adobe Flash Player –        version 16.0.0.305 (for Windows, iOS and Chrome)

Are you using a D-Link Router?
D-Link has begun to push out firmware updates for some of its home routers, to address three separate vulnerabilities that could allow remote code injection via access to the local area network, perform DNS hijacking, or exploit chipset utilities in the router firmware that expose configuration information.  The company said in an advisory that it will release several updates between now and March 10. The most critical flaw is a “ping” issue, which opens the door for all kinds of nefarious activity, according to the researchers that first discovered it.
Attention Seagate NAS Owners!
Thousands of Seagate Network Attached Storage (NAS) devices are vulnerable to a zero-day remote code execution (RCE) vulnerability that allows attacker to remotely get unauthorized root access to the drives.  Late last year security researcher OJ Reeves quietly notified Seagate that their Business Storage 2-Bay NAS products had a firmware vulnerability.  Seagate still hasn’t issued a firmware fix, so Reeves has now publicly disclosed the bug.
We hope that you find this information useful.  If you don’t want to receive these alerts any more, just Reply to this e-mail with the word UNSUBSCRIBE in the subject.
Thanks,
Jeff Hoffman and your friends at ACT Network Solutions
Security, Data Protection and Network Management are our specialties

ACT Network Solutions
Delivering Innovative IT Solutions for over 26 Years
700 Industrial Drive,  Suite H       Cary, IL      60013
(847) 639-7000                          jhoffman@act4networks.com

Friday, February 27, 2015

Malware, Spam and Hacking Updates for the week of February 27, 2015

Social Hacking in the office - How prepared are you for even the most basic hack?
3M Corporation recently conducted a “Visual Hacking Experiment”.  A white hat hacker was sent into the offices of eight companies posing as a temporary or part-time worker to try to hack sensitive or confidential information using only visual means. The information captured included employee contact lists, customer information, corporate financials, employee access and login information, and credentials or information about employees.

In 88 percent of attempts, the hacker was able to visually hack sensitive information from a worker’s computer screen or hard copy documents. These hacks generally were successful within 30 minutes of arrival. Worse yet, 70 percent of the time, the “visual hacker” wasn’t stopped by employees – even when he used a cell phone to take a picture of data being displayed on a worker’s screen. Virtually untraceable, visual hacking is a stealth threat vector to guard against as employees are more mobile and data is being accessed not only in the office but also in public places like airport lounges, public parks and coffee houses.


With identity and access information or login credentials (really, the “keys to the kingdom”) in the hands of the bad guys, our corporate data is at serious risk for a much larger data breach.  Often, we expect data theft to require sophisticated means in order to achieve results and sometimes it’s very easy and sometimes we don’t recognize when the threat is right there in front of us.

How do you train your staff to watch for Social Hacking at the office?
3 New E-mail  Malware Threats This Week
Cisco Security has detected significant activity related to spam email messages distributing malicious software.  Infected Email messages may look like these:

Subject:                    Dennys Invoice INV650988
Message Body:  
        To view the attached document, you will need the Microsoft Word installed on your system.
Infected File(s):         INV650988.doc                                       size = 32,768 bytes

Subject:                    New incoming fax
Message Body:          You have received a new fax.  John Clark
Infected File(s):         fax-23125.zip or fax-23125.exe                size = 27,136 bytes

Subject:                    Akeem Watson agent FEDEX
Message Body:  
        Dear Customer,   We attempted to deliver your item . . .

Infected File(s):        Package.zip /43208290483432.scr             size = 73,728
                              
Pack.zip / 43208290483432.scr                 size = 77,822
                              
Package.zip / 443645787823424455.scr     size = 73,728
These reports came from the Cisco Security Team and these exploits are reported to be widespread this week.
Fake e-mails referencing Payroll Information
This spam email message claims to contain payroll information for the recipient. The email message attempts to convince the recipient to open the attachment to view the details. However, the .zip attachment contains a malicious .exe file that, when executed, attempts to infect the system with malicious code.

Subject:                Payroll Received by Intuit
Message Body:      Dear ----------,  We received your payroll on October 9, 2013 at 4:55 PM .   Attached is a copy of your Remittance. Please click on the attachment in order to view it.

Please be aware that this is NOT a complete list and only highlights some of the most prevalent malware spams active this week.
 
Fake Pop-up loads exploits

 









The code within the pop-up redirects straight to a Fiesta exploit kit landing page. The landing page usually performs various checks and prepares the exploits that are going to get fired at the victim.  Break out your anti-malware toolkit if any user on your network encounters a pop-up like this.  This one is going to take a while to remove!

Word Document Exploit info from our friends at AlienVault –


We are seeing some especially tricky attacks these days related to the Sofacy (aka Sednit/APT28/Fancy Bear) threat group. One of their common tactics is to hide malicious payloads in Word documents and even in Word macros, exploiting known vulnerabilities. Some other delivery mechanisms we have seen related to this group have been traditional Spearphishing, website compromises, even redirects to a fake site designed to impersonate the user’s Outlook web mail portal.   Infected computers can spread the virus to critical systems and/or those that house sensitive data Backdoor and/or Command & Control mechanisms can put you at even greater risk to future and further compromise and possibly cause destruction/exfiltration of data.

See more at:
https://www.alienvault.com/blogs/security-essentials/sofacy-group#sthash.XR1ICKZz.dpuf


INTERESTING INDUSTRY HEADLINES THIS WEEK:
Target Breach Has Cost the Company $162 Million So Far
HyTrust president Eric Chiu suggests the total cost could eventually exceed $1 billion.
To read more, click here:  ESECURITYPLANET

----------------------------------------------------------------------------------------------

G
ot a question about malware you’d like answered
Just REPLY to this email with your question and the word QUESTION in the subject line
and we’ll try to answer it quickly for you.

We hope that you find this information useful.  If you don’t want to receive these alerts any more, just Reply to this e-mail with the word UNSUBSCRIBE in the subject.

Thanks,  Jeff Hoffman and your friends at ACT Network SolutionsSecurity, Data Protection and Network Management are our specialties

Do you have IT security concerns?  Call ACT @ (847) 639-7000






Delivering Innovative IT Solutions for over 26 Years
700 Industrial Drive,  Suite H       Cary, IL      60013
(847) 639-7000                          jhoffman@act4networks.com

Thursday, February 19, 2015

How Confidential Is Your G-mail, Yahoo and MSN email?

Data Theft is a frequent problem on the big “free” e-mail sites

Let’s face it, hacking email accounts, address books and using your e-mail address without your permission is BIG business and hacking the big “free” mail services is very rewarding for hackers looking for big paydays.  That’s the reason you see headlines like these so often:

“5 million Gmail passwords leaked”  CNN Money September 14, 2014

“Hackers attack Yahoo Mail accounts”  CNN Money January 30, 2014
Using these so-called free services is just an open invitation to hackers to take your information.

The best way to limit your exposure to these activities is to avoid these large targets on the Internet and use your own domain services and email servers.  Yes, small domains can be exploited too but hackers usually aim at the bigger hosts that contain more usable data.

Now let’s talk about privacy  

Google court filing says "g-mail users have no expectation of privacy" 

Did you ever ask yourself why all of these services offer “free” email accounts?   The answer is in 2 little words – DATA MINING.  They use your communications to accumulate data that they can sell.  Hackers want your email address to add to their spamming lists and also as cover for delivering malware and other illegal activities.

Google declared in a legal pleading in a data mining lawsuit in 2013:


"Just as a sender of a letter to a business colleague cannot be surprised that the recipient's assistant opens the letter, people who use web-based email today cannot be surprised if their emails are processed by the recipient's [e-mail provider] in the course of delivery. Indeed, 'a person has no legitimate expectation of privacy in information he voluntarily turns over to third parties.'"    


In business, first impressions are important!
Another great reason for having your own email services is it boosts you professional profile.  Have you ever looked at a senders email address, noted it was a “free” address like bob1234@gmail.com and wondered how big an operation that guy is running if he won’t spend a few bucks to have his own company name e-mail address?  Bob1234 may be a great guy but can you be sure he isn’t just some fly-by-night nobody? Is he using g-mail to hide who he really is because any bozo can get an email account there?  He sure doesn’t appear to be concerned about privacy, does he?  Did you ever notice that spammers frequently use the so-called “free” accounts?

Private email addresses with your own company name aren’t expensive.  ACT can set up your corporate e-mail service for as little as $14.95 per month with 10 email accounts plus we’ll host your own business web site at the same time.  Call ACT Network Solutions (847) 639-7000.  Mention this blog post and we'll throw in 2 extra months of service at no charge if you sign up for 1 year of service.

Friday, February 13, 2015

Weekly Security Update for the week of February 13, 2015 -Fake Amazon Alerts

Weekly Security Update for the week of February 13, 2015

If you haven’t updated your Windows this week, do it NOW!
One of the security bulletins released by Microsoft on Tuesday fixes a privilege escalation vulnerability which, according to researchers, can be exploited by malicious actors to bypass all the security measures in Windows by modifying a single bit.  The vulnerability (CVE-2015-0057), rated “important,” is caused by the improper handling of objects in memory. According to Microsoft, an attacker who manages to access a targeted system can gain elevated privileges and read arbitrary amounts of kernel memory, which would allow them to install software, view and change data, and create new accounts with full administrative rights.
Microsoft also just released nine update bundles to plug at least 55 distinct security vulnerabilities in its Windows operating system and other software. Three of the patches fix bugs in Windows that Microsoft considers “critical”.
New Malware opens a backdoor on your computer - BKDR_VAWTRAK.DOKR
This new malware is either dropped by other malware or downloaded from the Internet.  It is loaded onto an affected system via malicious macro code. With its backdoor capabilities, users affected by this malware may find the security of their systems compromised.

It executes commands from a remote malicious user, effectively compromising the affected system.  It also modifies the Internet Explorer Zone Settings and then deletes the initially executed copy of itself.

The primary threat this malware presents is data theft and potential participation in coordinated attacks directed by an external command and control server.

Here are tips from Trend Micro about properly removing data from your old computer

Many people don’t think about the risks that come with disposing of old computers and related gadgets. In truth, any device that can store data—old laptops, flash drives, data discs, smartphones, digital audio players, and the like—regardless if they’re still functioning properly, is a liable cause of information theft.
If you’re really concerned about your data privacy, you can do one of three things:
1.       Wipe your data. Instead of just deleting your old data, wiping makes sure that your old data is replaced. You can do this by using a trusted data wiping software that will overwrite all sectors of your laptop or PC.
2.       Degauss your drive. The process of degaussing involves magnetizing your machine’s hard drive, rendering it useless. After this process, no one will be able to access or store any data on it any longer.
3.      Wreck your drive, physically. This could be fun, but also a bit dangerous. When using power tools or the good old boot to destroy your device, make sure to wear protective gear. And once it’s all in pieces, make sure to throw it out properly. Check out electronics recycling or disposal centers who might find use for your junk.

Of course, these options are limited to data on PCs and laptops.  It’s a different matter altogether when it comes to data stored on mobile devices or even in the cloud.  The Trend Micro e-guide, “How To Erase Data Securely” has more information on how you can permanently be rid of your digital garbage on all devices and platforms.
Never underestimate what you throw away. Remember that one man’s trash can always be another one’s treasure.

Valentine’s Day spike in Socially Engineered Spam is in full swing
It’s time for everyone to be on their guard for the new flood of Valentine’s Day spam that’s already flooding mailboxes.
Early volume leaders feature links to Russian dating sites among others.  There’s nothing particularly new about the content, it’s just the time of year when spam like this begin to peak.  Remind your co-workers to be on their guard for new attempts to trick them into clicking on something they shouldn’t.
Be on the lookout!
Fake Amazon.com e-mails - Fake #Amazon support mail asks potential victims for address info and payment details.
Scareware pop-ups – There’s a new flurry of scammers pushing fake AdwCleaner in active scareware campaigns.

Scareware sample
Scareware Sample
 
Oh, and just one more thing!
Here’s a great article about protecting your on-line privacy from Jérôme Segura at Malwarebytes:


https://blog.malwarebytes.org/online-security/2015/02/10-tips-to-maintain-an-online-presence-in-a-privacy-hostile-world/


We hope that you find this information useful.  If you don’t want to receive these alerts any more, just Reply to this e-mail with the word UNSUBSCRIBE in the subject.

Thanks,
Jeff

Security, Data Protection and Network Management are our specialties
Delivering Innovative IT Solutions for over 26 years

Friday, February 6, 2015

Weekly Security Update for the week of February 6, 2015 - A new CryptoLocker variant that attacks data bases?

A new Cryptolocker-like variant now encrypts your data bases

Does your organization use a data base on-line for information sharing or on-line order taking through your web site or other external portal?   A new variant of the now “classic” CryptoLocker Trojan is now screwing with corporate on-line data bases.  Hackers are infecting web sites that have on-line data bases in an insidious new scheme to extort money from companies.  The short explanation of how it is done is that the hackers embed an encryption module in your web site that encrypts data as it is written to your data base and for a period of time the program also de-crypts it for viewing  to mask the fact that they are slowly corrupting your data over a period of about 6 months.  They do this long enough for your backup system to build a history of encrypted data  in your data base in your backups so that when they pull the plug on the decryption module, you’re stuck with a corrupted data base AND a corrupted backup so you can’t easily recover.  In the past, your escape from a ransom attempt was your ability to recover using your backed up data.  They’re now trying to screw with that too!

Security experts warn that this attack method could ensure denial of service on mission critical web apps more effectively than a DDoS. Traditional back-ups won’t help if typical retention intervals are used and it’s almost impossible, once infected, to recover without paying the ransom.
 
This exploit is still very new and there isn’t a clear direction yet on how to prevent infection but some experts think that file integrity monitoring tools might at least give you greater visibility into whether you’ve been infected.  If nothing else, we suggest making sure that your backup system has extended historical versioning that goes back at least 6 months and preferably a year.  We’ll keep you posted on any new developments on this new exploit.

Here’s another chilling thought.  While this is affecting on-line data bases only at present, it could be considered an early indicator that infecting internal data bases may be on the horizon for these hackers as they work out the details in this early “proof of concept” effort.

Apple iOS Now Targeted In Cyber Espionage Campaign

Kelly Jackson Higgins of Dark Reading reports – “Operation Pawn Storm, which has been tied to Russia by at least one security research firm, is using a specially crafted iOS app to surreptitiously steal from the mobile device text messages, contact lists, pictures, geo-location information, WiFi status of the device, lists of installed apps and processes -- and to record voice conversations, according to new Trend Micro research.
“The Cold War has returned in cyberspace, and Apple has become the gateway to western elites," says Tom Kellermann, chief cyber security officer with Trend Micro. "Pawn Storm has evolved to now incorporate proximity attacks against Western victims."”

Trend Micro researchers reported that they found two malicious iOS applications in Operation Pawn Storm. One is called XAgent (detected as IOS_XAGENT.A) and the other one uses the name of a legitimate iOS game, MadCap (detected as IOS_ XAGENT.B).

You can read the whole article here:  (Click here)

Another New Adobe Flash Zero-Day Exploit Used in Malvertising

Researchers have discovered another new zero-day exploit in Adobe Flash used in malvertisement attacks. The exploit affects the most recent version of Adobe Flash.   It appears to be executed through the use of the Angler Exploit Kit.  This is not the first exploit of Flash player this month.  Adobe has confirmed that this is a zero-day exploit and a patch should be available this week.

There’s a new security update available for Google Chrome

Google has released Chrome 40.0.2214.111 for Windows, Mac, and Linux to address multiple vulnerabilities.  If you haven’t updated your Chrome browser lately, now is the time.

Follow-up on last week’s article about click-fraud entitled “Click-fraud malware benefits YouTube scammers using your computer”
This week we had to help 2 clients who were infected by this malware so it is real and it is active in our area.  If your browsing appears to be sluggish, you may want to check for hidden browser sessions running behind your active window that are busily clicking on videos or ads to run up “pay per click” business activity outside of your view.

Thanks,
 
Jeff
 
Jeff Hoffman is a network security and information protection consultant with ACT Network Solutions.  He can be reached at jhoffman@act4networks.com

Monday, January 26, 2015

Windows 2003 Server loses support in July, 2015

Are you still running a server with Windows 2003 Server Edition?  You're running out of time to update or replace your server if you are.  All support including patch and security updates stop in July, 2015.

Windows 2003 is going the way of Windows XP and the Dodo and won't be supported after July so you'd better have plans to replace either the operating system or the entire server if you haven't already.

Microsoft only supports older versions of all of their software for 2 previous generations and with the impending release of their new Windows versions, Server 2003 has reached end of life.

The time to update is now.  Chances are that if you're running Windows 2003, your server is probably out of date too since that O/S stopped production in 2007 and that means that your server itself is probably 7-8 years old.  The recommended life expectancy of a server is about 5 years so you're flirting with danger running a server as the lifeblood of your network for that long.

If you're forced to use Windows 2003 because of an application software package that requires it, it's time to replace that sucker too.  Any publisher that hasn't kept their software current is a threat to your business and should be replaced just on general principle.

The time to update is NOW!

Jeff Hoffman, president of ACT Network Solutions can be reached at (847) 639-7000 or via e-mail at jhoffman@act4networks.com

HIPAA complaince and the need for Periodic Security Reviews

Are you just paying lip service to HIPAA compliance by ignoring ongoing security evaluations? If you are, it just might cost you!

Tiffany Robertson recently posted this update about Malware negligence and HIPAA on the WeComply blog: “The Department of Health and Human Services' (HHS) Office for Civil Rights (OCR) recently announced an agreement with a medical center to settle charges stemming from the center’s failure to prevent malwa
re from infecting its computers. The malware breached the ePHI of 2,743 individuals.

The medical center was fined $150,000 and agreed to implement a corrective action plan for violating the mandates of HIPAA’s Security Rule. Under the Security Rule, covered entities and business associates must implement appropriate administrative, physical and technical safeguards to protect the confidentiality, integrity and security of ePHI.

According to OCR, the medical center adopted policies to comply with the HIPAA Security Rule, but failed to follow them after putting them to paper. The medical center did not perform an accurate or thorough risk assessment for ePHI, nor did it implement the necessary policies, procedures or technical security measures to prevent unauthorized access to ePHI. Specifically, OCR maintains that the medical center’s failure to identify and address basic risks — e.g., not regularly updating firewalls and running outdated, unsupported software — was the direct cause of the introduction of malicious software into its systems.”

Have you had an IT security evaluation recently? Call us if you need one.
 
Jeff Hoffman, president of ACT Network Solutions
Delivering Innovative IT Solutions for over 26 years. 
I can be reached at (847) 639-7000 or via email at jhoffman@act4networks.com.

Friday, January 2, 2015

Is Heuristic Malware Detection Better Than Traditional Methods?


Heuristic analysis is an expert-based analysis technique that determines the susceptibility of a system towards particular threat/risk using various decision rules or weighing methods.  Heuristic analysis of malware essentially differs from traditional anti-malware analysis because it attempts to analyze software by what it attempts to do rather than what it specifically looks like.
Why traditional anti-virus techniques don’t work anymore
Traditional anti-virus programs use a list of known signatures for malware which is essentially a fingerprint of the code within that malware that makes it unique.  All a malware writer has to do to avoid detection is to frequently change that signature enough to avoid detection.
Heuristic analysis attempt to identify malware by what it does not just what it looks like.  While signatures change by the minute, the characteristics of what malwares try to do doesn’t change as fast.
Most antivirus programs that utilize heuristic analysis perform this function by executing the suspicious command strings within a specialized virtual machine or “sandbox” to see what it does effectively allowing a simulation of what would happen if that suspicious file were to be executed in the “real world”. It analyzes the commands as they are performed, looking for common viral activities such as replication, file overwrites, and attempts to hide their existence. If one or more of these virus-like actions are detected, the suspicious file is flagged as a potential virus, and the user alerted.
Another method of heuristic analysis is for the anti-virus program to de-compile suspicious programs and analyze the source code contained within. The source code of the suspicious file is compared to the source code of known viruses and virus-like activities. If a certain percentage of the source code matches with the code of known viruses or virus-like activities, the file is flagged, and the user alerted.
Is Heuristic Analysis effective?
While heuristic analysis is capable of detecting many previously unknown viruses and new variants of current viruses, it does operate on the basis of experience with known malware structures.  It is likely to miss new malware and variants that use previously unknown techniques or methods of operation not found in known viruses. Hence, the effectiveness is fairly low regarding accuracy.  It can also be susceptible to false-positives for legitimate software that uses similar or unfamiliar coding techniques that can disable that software because it “acts” like a virus.
As new viruses are discovered by human researchers, information about them is added to the heuristic analysis engine, thereby providing new criteria to detect new viruses.  Each vendor’s analysis techniques are unique and mostly proprietary so effectiveness can vary significantly from one company or product to the next.
Should you use it?
Let’s face reality.  Signature-based anti-virus doesn’t work very well any more.  Sure, Heuristic isn’t the perfect solution, but you’re still better off with it than without it.  Any new A/V products or firewall components you purchase should have a Heuristic component.  You should just be aware that it’s NOT going to catch everything and it may even occasionally knock out a legitimate program if you’re not careful.
Is the product you’re using effective? 
It’s important to use a recognized leader in malware protection.  There are professional ratings reports published each year that rank A/V products.  My particular favorite rating organization is Gartner Research and each year they rank vendors using their Magic Quadrant reviews.  They rank products based upon how well they work and how complete is the vendors offering.  Last year 5 Security vendors were ranked as Leaders.  If your vendor was listed in their Leaders quadrant, you can be pretty well assured that you’re getting the most bang for your buck in this category.  Be aware, that there are A LOT of A/V vendors that don’t even make the chart at all, let alone get into the Leader category.  My advice is to stick with one of the Leaders.  If you’re using a FREEWARE anti-virus product, you’re just asking for trouble.    

Jeff Hoffman is a network security and information protection consultant with ACT Network Solutions.  He can be reached at jhoffman@act4networks.com

 

Sunday, December 21, 2014

Over 24,200 Reported HIPAA Data Breaches in 9 Months! REALLY?

Devin Poehlman of ID Experts recently posted the following eye-opening statistics about HIPAA related security breaches.
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) website indicates that there were 1,100 data breaches involving 500 or more records during the first nine months after the HIPAA Omnibus Rule took effect on September 23, 2013.
They also noted that for every breach of 500 or more records there were around 22 breaches of less than 500 records or approximately 24,200 breaches in 9 months.
He also cited estimates that only 2% or less of security and privacy incidents actually get classified as a data breach so using simple math we can project that there could be as many as 1.6 million incidents (not records, BREACH INCIDENTS!) involving health data each and every year in the health care industry.
Devin goes on to say “Given this level of frequency of incidents, I think that it isn’t a stretch to conclude that the management of incidents – capturing the facts, assessing whether they are breaches, carrying out regulatory notifications – is something that most larger organizations with some health data are doing on a daily and weekly basis. But it hasn’t become a “mission critical” function in most of these organizations. Something that is carried out like other day-to-day operational functions. Like billing. Or payroll.  Yet, the privacy and security of health data is one of the most highly regulated areas by federal and state authorities. And regulators have become draconian in assessing fines, penalties, and corrective action plans to organizations that can stand up to their scrutiny, especially when there is a data breach.”
Have you examined your reporting process lately?  What are you doing to make your reporting and reaction processes better?