Update Regarding DDoS Event Against Dyn Managed DNS on October 21, 2016
Incident Report for Dyn, Inc.
Update
The Dyn Analysis Summary of Friday, October 21st DDoS can be found here: http://dyn.com/blog/dyn-analysis-summary-of-friday-october-21-attack/
Posted about 20 hours ago. Oct 26, 2016 - 16:43 UTC
Monitoring
Customers seeking additional information pertinent to the incident may reference the following, extended statement: http://hub.dyn.com/dyn-blog/dyn-statement-on-10-21-2016-ddos-attack
Posted 5 days ago. Oct 22, 2016 - 21:30 UTC
Identified
This Preliminary Findings Report is to provide additional detail in connection with an incident that began on October 21, 2016 at approximately 11:10 UTC and lasted until approximately 17:45 UTC
Dyn is dedicated to delivering the highest quality of service, and as such, we take any customer impacting events very seriously. Below you will find a preliminary analysis of the event. A more in-depth analysis will be distributed in the form of a Root Cause Analysis report at a later date.
Service Affected: Managed DNS
Event cause:
On Friday October 21, 2016 at approximately 11:10 UTC, Dyn came under attack by a large Distributed Denial of Service (DDoS) attack against our Managed DNS infrastructure in the US-East region. Customers affected may have seen regional resolution failures in US-East and intermittent spikes in latency globally. Dyn’s engineers were able to successfully mitigate the attack at approximately 13:20 UTC, and shortly after, the attack subsided. See original status post here: https://www.dynstatus.com/incidents/nlr4yrr162t8.
At roughly 15:50 UTC a second DDoS attack began against the Managed DNS platform. This attack was distributed in a more global fashion. Affected customers may have seen intermittent resolution issues as well as increased global latency. At approximately 17:00 UTC, our engineers were again able to mitigate the attack and service was restored.
At Dyn, we take every incident seriously and work hard to ensure we deliver the service our customers have come to expect. We will continue to evaluate every situation with the goal of improving our systems and processes to deliver the utmost customer experience. Thank you for your continued support.
Oct 21, 2016 - 22:11 UTC
This incident affects: Dyn Managed DNS (Anycast Network).
- wong chee tat :)
Showing posts with label cyberrange. Show all posts
Showing posts with label cyberrange. Show all posts
Thursday, October 27, 2016
DDoS attack on StarHub first of its kind on Singapore's telco infrastructure: CSA, IMDA
DDoS attack on StarHub first of its kind on Singapore's telco infrastructure: CSA, IMDA
Posted 26 Oct 2016 21:20 Updated 26 Oct 2016 23:35
SINGAPORE: The Distributed Denial of Service (DDoS) attacks on StarHub’s broadband network were the first of that nature on Singapore's telco infrastructure, the Cyber Security Agency of Singapore (CSA) and Infocomm Media Development Authority (IMDA) said on Wednesday evening (Oct 26).
This comes after the telco revealed in a media briefing on Wednesday that compromised devices such as webcams and routers owned by its customers led to the DDoS attacks.
In a joint statement, CSA and IMDA said attacks on Domain Name Services (DNS), as seen in StarHub’s case, are “generally rare”, “although the latest Dyn incident in US has shown that it is surfacing as an emerging trend”.
The agencies added that in DDoS attacks, attackers usually scan for vulnerable Internet-connected devices commonly known as "botnet" and employ a list of techniques - such as password cracking - to gain access to them.
“Any Internet-connected device, from WiFi routers to printers to CCTVs, can inadvertently be part of a network of ‘bots’ that can be activated to attack other systems,” CSA and IMDA said, adding that there is no foolproof solution as digital systems are increasingly connected.
As such, telcos must ensure they have “resilient and robust” systems, and put in place measures to quickly detect and respond to such attacks, so as to avoid disruption of services to their subscribers, CSA and IMDA added.
They reiterated that they are working “closely” with StarHub to investigate the matter, and strengthen the telco’s infrastructure and processes, and said they have advised other telcos in Singapore to step up their defences in case there are similar disruptions to their systems.
Members of the public are also advised to adopt “good cyber hygiene practices” to secure their devices. SingCERT will publish an advisory on what businesses and individuals should do to ensure their Internet-connected devices are secure, CSA and IMDA said.
BUSINESSES SHOULD MAKE CYBER SECURITY A PRIORITY: YAACOB
Communications and Information Minister Yaacob Ibrahim called on businesses to take action to address their specific cyber security needs, even as the Government steps up efforts to help them stay safe.
Speaking at an Asia Pacific cyber security summit on Wednesday, Dr Yaacob said the Government has been consistent in pursuing cyber security development, working with multiple stakeholders, including businesses and international partners. This includes launching the national cyber security strategy earlier this month, and developing a multi-tiered cyber security response plan.
A new Cybersecurity Act is also in the pipeline.
But Dr Yaacob emphasised that the Government cannot do it alone, and urged companies to make cyber security a priority.
"Cyber security should not be seen as a cost, but as an investment to manage risk. Under-investment in cyber security does not mean 'business-as-usual'. Weak cyber defences suffering from under-investment could be breached more easily, leading to disruption of business activities and significant losses," the minister said.
- CNA/dl
- wong chee tat :)
Posted 26 Oct 2016 21:20 Updated 26 Oct 2016 23:35
SINGAPORE: The Distributed Denial of Service (DDoS) attacks on StarHub’s broadband network were the first of that nature on Singapore's telco infrastructure, the Cyber Security Agency of Singapore (CSA) and Infocomm Media Development Authority (IMDA) said on Wednesday evening (Oct 26).
This comes after the telco revealed in a media briefing on Wednesday that compromised devices such as webcams and routers owned by its customers led to the DDoS attacks.
In a joint statement, CSA and IMDA said attacks on Domain Name Services (DNS), as seen in StarHub’s case, are “generally rare”, “although the latest Dyn incident in US has shown that it is surfacing as an emerging trend”.
The agencies added that in DDoS attacks, attackers usually scan for vulnerable Internet-connected devices commonly known as "botnet" and employ a list of techniques - such as password cracking - to gain access to them.
“Any Internet-connected device, from WiFi routers to printers to CCTVs, can inadvertently be part of a network of ‘bots’ that can be activated to attack other systems,” CSA and IMDA said, adding that there is no foolproof solution as digital systems are increasingly connected.
As such, telcos must ensure they have “resilient and robust” systems, and put in place measures to quickly detect and respond to such attacks, so as to avoid disruption of services to their subscribers, CSA and IMDA added.
They reiterated that they are working “closely” with StarHub to investigate the matter, and strengthen the telco’s infrastructure and processes, and said they have advised other telcos in Singapore to step up their defences in case there are similar disruptions to their systems.
Members of the public are also advised to adopt “good cyber hygiene practices” to secure their devices. SingCERT will publish an advisory on what businesses and individuals should do to ensure their Internet-connected devices are secure, CSA and IMDA said.
BUSINESSES SHOULD MAKE CYBER SECURITY A PRIORITY: YAACOB
Communications and Information Minister Yaacob Ibrahim called on businesses to take action to address their specific cyber security needs, even as the Government steps up efforts to help them stay safe.
Speaking at an Asia Pacific cyber security summit on Wednesday, Dr Yaacob said the Government has been consistent in pursuing cyber security development, working with multiple stakeholders, including businesses and international partners. This includes launching the national cyber security strategy earlier this month, and developing a multi-tiered cyber security response plan.
A new Cybersecurity Act is also in the pipeline.
But Dr Yaacob emphasised that the Government cannot do it alone, and urged companies to make cyber security a priority.
"Cyber security should not be seen as a cost, but as an investment to manage risk. Under-investment in cyber security does not mean 'business-as-usual'. Weak cyber defences suffering from under-investment could be breached more easily, leading to disruption of business activities and significant losses," the minister said.
- CNA/dl
- wong chee tat :)
Labels:
2016,
computer network,
computer networking,
cyber security,
cyberrange,
cyberspace,
ddos,
dns,
dos,
dyn,
Google Public DNS service,
market,
mobile network,
network,
oct,
opportunities,
outages,
router,
StarHub
Singapore's cybersecurity skills shortage: Why it matters
Singapore's cybersecurity skills shortage: Why it matters
By Linette Lim Posted 14 Oct 2016 15:51 Updated 14 Oct 2016 16:00
SINGAPORE: In his speech launching Singapore’s national cybersecurity strategy earlier this week, Prime Minister Lee Hsien Loong warned of cyberattacks and threats “becoming more frequent and sophisticated, with more severe consequences”.
He pointed to how a cyberattack on the power grid in Ukraine last December left many Ukrainians without electricity for hours, and how hackers used malware to withdraw more than US$2 million (S$2.77 million) from ATMs in Taiwan in July this year. Closer to home, he said that there have been attacks on government networks and on the financial sector.
According to a 2014 report from Center for Strategic and International Studies, cybercrime costs Singapore an estimated S$1.25 billion annually.
Yet there is a decidedly acute shortage of IT security specialists that can be engaged to help fend off such online threats.
According to Communications and Information Minister Yaacob Ibrahim, there were 15,000 vacancies in the information and communications technology (ICT) sector last year, unchanged from 2014. More than two-thirds of these vacancies, he said, were for professionals, managers, executives and technicians (PMETs) or technical specialists in areas such as development, network and infrastructure, cybersecurity and data analytics.
Additionally, 2012 data from the Economic Development Board (EDB) showed that just 0.8 per cent of Singapore’s 144,300 ICT workers were IT security specialists, with a particularly acute shortfall in the middle and senior tiers.
MANPOWER GAP HINDERING CYBERCRIME FIGHT
This is why for vendors like Quann, which hires more than 300 certified security professionals in the region, a global shortage of cybersecurity manpower means fighting cybercrime is proving to be an uphill battle.
“There is a distinct (manpower and skills) gap, and the gap has widened. The proxy for that is the wage growth that we’ve seen in this sector. Wages have gone up quite substantially in the last two to three years. Based on some reports by third-party consultancies, wages are estimated to have gone up by 20 per cent per year, over the last couple of years,” said Quann’s managing director Foo Siang-tse.
According to Mr Foo, increasing digitisation of customer and business records and the proliferation of interconnected devices have resulted in greater avenues for cybercriminals, but “until recently”, educational institutions have not expanded capacity quickly enough to keep pace with demand in the sector.
To address this, part of the national cybersecurity strategy is to boost the cybersecurity profession in a number of ways. This includes instituting clear career pathways, promoting certification, and working with the industry and institutes of higher learning to attract new graduates and convert existing professionals from related fields.
WHAT ARE THE SKILLS NEEDED?
One of these organisations is ISACA, the international professional body formerly known as the Information Systems Audit and Control Association. Its Singapore Chapter says the Government is working with industry groups like theirs to offer training and certification programmes.
“Skills that are lacking now are in the areas of intrusion detection, security architecture and analysis, security incident management, secure software development, incident response and recovery,” said Mr John Lee, President of ISACA Singapore Chapter.
“Singapore is a global financial hub with high-end manufacturing and developed service industry. The need to safeguard against a major cyber breach is paramount to prevent erosion of trust by external stakeholders.”
Among the IHLs, the Singapore University of Technology (SUTD) only opened its doors four years ago. Professor Aditya Mathur, who oversees the university’s Information Systems Technology and Design pillar, said he has seen a rise in student enrollments and a growing number of students picking security classes.
“SUTD is not only offering courses in cybersecurity at the undergraduate level but also conducting outreach programmes aimed at raising cybersecurity awareness among secondary school students,” Prof Aditya added.
TAPPING ON EXISTING TALENT POOL
But it will be some time before these students join the workforce and contribute to the core of local cybersecurity talent. In the meanwhile, Mr Foo says Quann is doing its best to meet the manpower challenge through on-the-job training, or through converting existing IT professionals with adjacent skillsets.
The local company is one of four participating in the Cyber Security Associates and Technologists (CSAT) programme, which equips ICT professionals with three years’ working experience to pick up the requisite skills to switch sectors. The other training partners are Singtel, ST Electronics and Accel Systems and Technologies.
Some business leaders who oversee ongoing efforts to help build up Singapore's cybersecurity manpower pool include Mr Boye Vanell from BAE Systems (top-left); Quann’s Mr Foo Siang-tse (bottom-left); and Microsoft Singapore’s Ms Jessica Tan (right). (Photos: BAE Systems, Quann, Microsoft Singapore).
While Quann partners tertiary institutions like the National University of Singapore, the Singapore Management University, and Ngee Ann Polytechnic to get access to talent, others, like British multinational BAE Systems, aim to build up the cybersecurity ecosystem through collaborating with researchers and helping to incubate startup ideas.
One outcome of its partnership with Nanyang Technological University is a threat operating model designed by postgraduate students, built using BAE System’s tools and techniques.
“You need to create the interest in the industry. You do that by running research programmes, and you do that by bringing niche technology to startup companies to help close the gaps that customers face,” said Mr Boye Vanell, Regional Director of Asia at BAE Systems.
Microsoft Singapore’s Managing Director Jessica Tan, who oversaw the company’s opening of a new Transparency Center and Cybersecurity Center in Singapore this month, told Channel NewsAsia that apart from technical skills, other important attributes for cybersecurity professionals include “a growth mindset, curiosity, learning and resilience".
She said: “What is critical is building an ICT foundation in every student, which they can then extend and apply to every field they pursue, regardless of whether it is in biomedicine, behavioural economics or digital manufacturing, to name a few. ICT will touch every facet of the industry and government.”
According to Ms Tan, given that more citizens’ lives are touched by technology - at home, in schools and in the workplace - the talent pipeline of cybersecurity professionals is “both an economic and security imperative for Singapore”. This implies the difficulty in relying too heavily on foreign cybersecurity professionals to plug the gaps.
The unique nature of the industry also means it is relatively labour-intensive, and there are limits to plugging the gaps with technology like big data analytics.
“At the end of the day, the person at the other end of the kill chain - the perpetrator - is still a human being. Notwithstanding that fact that we have our own R&D labs, we’re looking at tapping on big data and threat intelligence - if the adversary is human, we need humans on our side,” said Mr Foo.
- CNA/ll
- wong chee tat :)
By Linette Lim Posted 14 Oct 2016 15:51 Updated 14 Oct 2016 16:00
SINGAPORE: In his speech launching Singapore’s national cybersecurity strategy earlier this week, Prime Minister Lee Hsien Loong warned of cyberattacks and threats “becoming more frequent and sophisticated, with more severe consequences”.
He pointed to how a cyberattack on the power grid in Ukraine last December left many Ukrainians without electricity for hours, and how hackers used malware to withdraw more than US$2 million (S$2.77 million) from ATMs in Taiwan in July this year. Closer to home, he said that there have been attacks on government networks and on the financial sector.
According to a 2014 report from Center for Strategic and International Studies, cybercrime costs Singapore an estimated S$1.25 billion annually.
Yet there is a decidedly acute shortage of IT security specialists that can be engaged to help fend off such online threats.
According to Communications and Information Minister Yaacob Ibrahim, there were 15,000 vacancies in the information and communications technology (ICT) sector last year, unchanged from 2014. More than two-thirds of these vacancies, he said, were for professionals, managers, executives and technicians (PMETs) or technical specialists in areas such as development, network and infrastructure, cybersecurity and data analytics.
Additionally, 2012 data from the Economic Development Board (EDB) showed that just 0.8 per cent of Singapore’s 144,300 ICT workers were IT security specialists, with a particularly acute shortfall in the middle and senior tiers.
MANPOWER GAP HINDERING CYBERCRIME FIGHT
This is why for vendors like Quann, which hires more than 300 certified security professionals in the region, a global shortage of cybersecurity manpower means fighting cybercrime is proving to be an uphill battle.
“There is a distinct (manpower and skills) gap, and the gap has widened. The proxy for that is the wage growth that we’ve seen in this sector. Wages have gone up quite substantially in the last two to three years. Based on some reports by third-party consultancies, wages are estimated to have gone up by 20 per cent per year, over the last couple of years,” said Quann’s managing director Foo Siang-tse.
According to Mr Foo, increasing digitisation of customer and business records and the proliferation of interconnected devices have resulted in greater avenues for cybercriminals, but “until recently”, educational institutions have not expanded capacity quickly enough to keep pace with demand in the sector.
To address this, part of the national cybersecurity strategy is to boost the cybersecurity profession in a number of ways. This includes instituting clear career pathways, promoting certification, and working with the industry and institutes of higher learning to attract new graduates and convert existing professionals from related fields.
WHAT ARE THE SKILLS NEEDED?
One of these organisations is ISACA, the international professional body formerly known as the Information Systems Audit and Control Association. Its Singapore Chapter says the Government is working with industry groups like theirs to offer training and certification programmes.
“Skills that are lacking now are in the areas of intrusion detection, security architecture and analysis, security incident management, secure software development, incident response and recovery,” said Mr John Lee, President of ISACA Singapore Chapter.
“Singapore is a global financial hub with high-end manufacturing and developed service industry. The need to safeguard against a major cyber breach is paramount to prevent erosion of trust by external stakeholders.”
Among the IHLs, the Singapore University of Technology (SUTD) only opened its doors four years ago. Professor Aditya Mathur, who oversees the university’s Information Systems Technology and Design pillar, said he has seen a rise in student enrollments and a growing number of students picking security classes.
“SUTD is not only offering courses in cybersecurity at the undergraduate level but also conducting outreach programmes aimed at raising cybersecurity awareness among secondary school students,” Prof Aditya added.
TAPPING ON EXISTING TALENT POOL
But it will be some time before these students join the workforce and contribute to the core of local cybersecurity talent. In the meanwhile, Mr Foo says Quann is doing its best to meet the manpower challenge through on-the-job training, or through converting existing IT professionals with adjacent skillsets.
The local company is one of four participating in the Cyber Security Associates and Technologists (CSAT) programme, which equips ICT professionals with three years’ working experience to pick up the requisite skills to switch sectors. The other training partners are Singtel, ST Electronics and Accel Systems and Technologies.
Some business leaders who oversee ongoing efforts to help build up Singapore's cybersecurity manpower pool include Mr Boye Vanell from BAE Systems (top-left); Quann’s Mr Foo Siang-tse (bottom-left); and Microsoft Singapore’s Ms Jessica Tan (right). (Photos: BAE Systems, Quann, Microsoft Singapore).
While Quann partners tertiary institutions like the National University of Singapore, the Singapore Management University, and Ngee Ann Polytechnic to get access to talent, others, like British multinational BAE Systems, aim to build up the cybersecurity ecosystem through collaborating with researchers and helping to incubate startup ideas.
One outcome of its partnership with Nanyang Technological University is a threat operating model designed by postgraduate students, built using BAE System’s tools and techniques.
“You need to create the interest in the industry. You do that by running research programmes, and you do that by bringing niche technology to startup companies to help close the gaps that customers face,” said Mr Boye Vanell, Regional Director of Asia at BAE Systems.
Microsoft Singapore’s Managing Director Jessica Tan, who oversaw the company’s opening of a new Transparency Center and Cybersecurity Center in Singapore this month, told Channel NewsAsia that apart from technical skills, other important attributes for cybersecurity professionals include “a growth mindset, curiosity, learning and resilience".
She said: “What is critical is building an ICT foundation in every student, which they can then extend and apply to every field they pursue, regardless of whether it is in biomedicine, behavioural economics or digital manufacturing, to name a few. ICT will touch every facet of the industry and government.”
According to Ms Tan, given that more citizens’ lives are touched by technology - at home, in schools and in the workplace - the talent pipeline of cybersecurity professionals is “both an economic and security imperative for Singapore”. This implies the difficulty in relying too heavily on foreign cybersecurity professionals to plug the gaps.
The unique nature of the industry also means it is relatively labour-intensive, and there are limits to plugging the gaps with technology like big data analytics.
“At the end of the day, the person at the other end of the kill chain - the perpetrator - is still a human being. Notwithstanding that fact that we have our own R&D labs, we’re looking at tapping on big data and threat intelligence - if the adversary is human, we need humans on our side,” said Mr Foo.
- CNA/ll
- wong chee tat :)
NUS and Singtel launch cybersecurity lab
NUS and Singtel launch cybersecurity lab
By Kimberly Spykerman Posted 24 Oct 2016 11:43 Updated 25 Oct 2016 00:15
SINGAPORE: The National University of Singapore (NUS) and Singtel on Monday (Oct 24) launched their joint cybersecurity laboratory aimed at protecting consumers against security breaches, data leaks and other online attacks.
Over the next five years, S$43 million from NUS, Singtel, and the National Research Foundation (NRF) will be pumped into the lab. "Such public-private R&D collaboration aligns public research to industry needs, and accelerates innovations to market," said Deputy Prime Minister Teo Chee Hean, who is also NRF's Chairman, at the launch event.
The new laboratory will focus on areas such as network, data and cloud computing security, among others.
Singtel CEO of Group Enterprise Bill Chang pointed out that many enterprises are constantly challenged by the increasingly sophisticated nature of cyber threats, and the new lab will allow them to develop and bring to market cybersecurity offerings more quickly to help these companies.
"What really differentiates this lab from other initiatives is the fact that we have an industrial partner,” said director of NUS-Singtel Cyber Security Research and Development Lab professor David Rosenblum. “So, they have very significant business problems that are related to cybersecurity, and the researchers at NUS are going to be exposed to these business problems.”
The lab will also increase Singapore's pool of cybersecurity professionals and raise their game, hosting 100 researchers and training 120 new cybersecurity professionals over the next five years.
"This will develop a strong talent pool critical to Singapore. The training will equip them with deep expertise in this growing area, and prepare them for employment opportunities, not just with Singtel, but also in the public sector and other companies," said Mr Teo.
The national cybersecurity strategy, which was announced by Prime Minister Lee Hsien Loong earlier this month, aims to boost the cybersecurity profession. This includes instituting clear career pathways, promoting certification, and working with the industry and institutes of higher learning to attract new graduates and convert existing professionals from related fields.
Singtel said it does not rule out collaborating with the other telcos in research and capability building, or in making the solutions commercially available to them.
- CNA/kk
- wong chee tat :)
By Kimberly Spykerman Posted 24 Oct 2016 11:43 Updated 25 Oct 2016 00:15
SINGAPORE: The National University of Singapore (NUS) and Singtel on Monday (Oct 24) launched their joint cybersecurity laboratory aimed at protecting consumers against security breaches, data leaks and other online attacks.
Over the next five years, S$43 million from NUS, Singtel, and the National Research Foundation (NRF) will be pumped into the lab. "Such public-private R&D collaboration aligns public research to industry needs, and accelerates innovations to market," said Deputy Prime Minister Teo Chee Hean, who is also NRF's Chairman, at the launch event.
The new laboratory will focus on areas such as network, data and cloud computing security, among others.
Singtel CEO of Group Enterprise Bill Chang pointed out that many enterprises are constantly challenged by the increasingly sophisticated nature of cyber threats, and the new lab will allow them to develop and bring to market cybersecurity offerings more quickly to help these companies.
"What really differentiates this lab from other initiatives is the fact that we have an industrial partner,” said director of NUS-Singtel Cyber Security Research and Development Lab professor David Rosenblum. “So, they have very significant business problems that are related to cybersecurity, and the researchers at NUS are going to be exposed to these business problems.”
The lab will also increase Singapore's pool of cybersecurity professionals and raise their game, hosting 100 researchers and training 120 new cybersecurity professionals over the next five years.
"This will develop a strong talent pool critical to Singapore. The training will equip them with deep expertise in this growing area, and prepare them for employment opportunities, not just with Singtel, but also in the public sector and other companies," said Mr Teo.
The national cybersecurity strategy, which was announced by Prime Minister Lee Hsien Loong earlier this month, aims to boost the cybersecurity profession. This includes instituting clear career pathways, promoting certification, and working with the industry and institutes of higher learning to attract new graduates and convert existing professionals from related fields.
Singtel said it does not rule out collaborating with the other telcos in research and capability building, or in making the solutions commercially available to them.
- CNA/kk
- wong chee tat :)
Sunday, October 23, 2016
Cyber attacks disrupt PayPal, Twitter, other sites
Cyber attacks disrupt PayPal, Twitter, other sites
Posted 21 Oct 2016 22:30 Updated 22 Oct 2016 11:15
June 24, 2013. REUTERS/Kacper Pempel/Files
REUTERS: Hackers unleashed a complex attack on the internet through common devices like webcams and digital recorders and cut access to some of the world's best known websites on Friday, a stunning breach of global internet stability.
The attacks struck Twitter, Paypal, Spotify and other customers of an infrastructure company in New Hampshire called Dyn, which acts as a switchboard for internet traffic.
The attackers used hundreds of thousands of internet-connected devices that had previously been infected with a malicious code that allowed them to cause outages that began in the Eastern United States and then spread to other parts of the country and Europe.
"The complexity of the attacks is what’s making it very challenging for us," said Dyn’s chief strategy officer, Kyle York. The U.S. Department of Homeland Security and the Federal Bureau of Investigation said they were investigating.
The disruptions come at a time of unprecedented fears about the cyber threat in the United States, where hackers have breached political organizations and election agencies.
Friday's outages were intermittent and varied by geography. Users complained they could not reach dozens of internet destinations including Mashable, CNN, the New York Times, the Wall Street Journal, Yelp and some businesses hosted by Amazon.com Inc .
Dyn said attacks were coming from millions of internet addresses, making it one of the largest attacks ever seen. Security experts said it was an especially potent type of distributed denial-of-service attack, or DDoS, in which attackers flood the targets with so much junk traffic that they freeze up.
VULNERABILITIES EXPLOITED
Dyn said that at least some of the malicious traffic was coming from connected devices, including webcams and digital video recorders, that had been infected with control software named Mirai. Security researchers have previously raised concerns that such connected devices, sometimes referred to as the Internet of Things, lack proper security.
The Mirai code was dumped on the internet about a month ago, and criminal groups are now charging to employ it in cyber attacks, said Allison Nixon, director of security research at Flashpoint, which was helping Dyn analyse the attack.
Dale Drew, chief security officer at communications provider Level 3, said that other networks of compromised machines were also used in Friday's attack, suggesting that the perpetrator had rented access to several so-called botnets.
The attackers took advantage of traffic-routing services such as those offered by Alphabet Inc's Google and Cisco Systems Inc's OpenDNS to make it difficult for Dyn to root out bad traffic without also interfering with legitimate inquiries, Drew said.
"Dyn can't simply block the (Internet Protocol) addresses they are seeing, because that would be blocking Google or OpenDNS," said Matthew Prince, CEO of security and content delivery firm CloudFlare. "These are nasty attacks, some of the hardest to protect against."
GOVERNMENT WARNED OF ATTACKS
Drew and Nixon both said that the makers of connected devices needed to do far more to make sure that the gadgets can be updated after security flaws are discovered.
Big businesses should also have multiple vendors for core services like routing internet traffic, and security experts said those Dyn customers with backup domain name service providers would have stayed reachable.
The Department of Homeland Security last week issued a warning about attacks from the Internet of Things, following the release of the code for Mirai.
Attacking a large domain name service provider like Dyn can create massive disruptions because such firms are responsible for forwarding large volumes of internet traffic.
Dyn said it had resolved one morning attack, which disrupted operations for about two hours, but disclosed a second a few hours later that was causing further disruptions. By Friday evening it was fighting a third.
Amazon's web services division, one of the world's biggest cloud computing companies, reported that the issue temporarily affected users in Western Europe. Twitter and some news sites could not be accessed by some users in London late on Friday evening.
PayPal Holdings Inc said that the outage prevented some customers in "certain regions" from making payments. It apologised for the inconvenience and said that its networks had not been hacked.
A month ago, security guru Bruce Schneier wrote that someone, probably a country, had been testing increasing levels of denial-of-service attacks against unnamed core internet infrastructure providers in what seemed like a test of capability.
Nixon said there was no reason to think a national government was behind Friday's assaults, but attacks carried out on a for-hire basis are famously difficult to attribute.
(Reporting by Joseph Menn in San Francisco, Jim Finkle in Boston and Dustin Volz in Washington. Additional reporting by Eric Auchard in Frankurt, Malathi Nayak in New York, Jeff Mason and Mark Hosenball in Washington, Adrian Croft and Frances Kerry in London; Editing by Bill Trott, Lisa Shumaker and Jonathan Weber)
- Reuters
- wong chee tat :)
Posted 21 Oct 2016 22:30 Updated 22 Oct 2016 11:15
June 24, 2013. REUTERS/Kacper Pempel/Files
REUTERS: Hackers unleashed a complex attack on the internet through common devices like webcams and digital recorders and cut access to some of the world's best known websites on Friday, a stunning breach of global internet stability.
The attacks struck Twitter, Paypal, Spotify and other customers of an infrastructure company in New Hampshire called Dyn, which acts as a switchboard for internet traffic.
The attackers used hundreds of thousands of internet-connected devices that had previously been infected with a malicious code that allowed them to cause outages that began in the Eastern United States and then spread to other parts of the country and Europe.
"The complexity of the attacks is what’s making it very challenging for us," said Dyn’s chief strategy officer, Kyle York. The U.S. Department of Homeland Security and the Federal Bureau of Investigation said they were investigating.
The disruptions come at a time of unprecedented fears about the cyber threat in the United States, where hackers have breached political organizations and election agencies.
Friday's outages were intermittent and varied by geography. Users complained they could not reach dozens of internet destinations including Mashable, CNN, the New York Times, the Wall Street Journal, Yelp and some businesses hosted by Amazon.com Inc .
Dyn said attacks were coming from millions of internet addresses, making it one of the largest attacks ever seen. Security experts said it was an especially potent type of distributed denial-of-service attack, or DDoS, in which attackers flood the targets with so much junk traffic that they freeze up.
VULNERABILITIES EXPLOITED
Dyn said that at least some of the malicious traffic was coming from connected devices, including webcams and digital video recorders, that had been infected with control software named Mirai. Security researchers have previously raised concerns that such connected devices, sometimes referred to as the Internet of Things, lack proper security.
The Mirai code was dumped on the internet about a month ago, and criminal groups are now charging to employ it in cyber attacks, said Allison Nixon, director of security research at Flashpoint, which was helping Dyn analyse the attack.
Dale Drew, chief security officer at communications provider Level 3, said that other networks of compromised machines were also used in Friday's attack, suggesting that the perpetrator had rented access to several so-called botnets.
The attackers took advantage of traffic-routing services such as those offered by Alphabet Inc's Google and Cisco Systems Inc's OpenDNS to make it difficult for Dyn to root out bad traffic without also interfering with legitimate inquiries, Drew said.
"Dyn can't simply block the (Internet Protocol) addresses they are seeing, because that would be blocking Google or OpenDNS," said Matthew Prince, CEO of security and content delivery firm CloudFlare. "These are nasty attacks, some of the hardest to protect against."
GOVERNMENT WARNED OF ATTACKS
Drew and Nixon both said that the makers of connected devices needed to do far more to make sure that the gadgets can be updated after security flaws are discovered.
Big businesses should also have multiple vendors for core services like routing internet traffic, and security experts said those Dyn customers with backup domain name service providers would have stayed reachable.
The Department of Homeland Security last week issued a warning about attacks from the Internet of Things, following the release of the code for Mirai.
Attacking a large domain name service provider like Dyn can create massive disruptions because such firms are responsible for forwarding large volumes of internet traffic.
Dyn said it had resolved one morning attack, which disrupted operations for about two hours, but disclosed a second a few hours later that was causing further disruptions. By Friday evening it was fighting a third.
Amazon's web services division, one of the world's biggest cloud computing companies, reported that the issue temporarily affected users in Western Europe. Twitter and some news sites could not be accessed by some users in London late on Friday evening.
PayPal Holdings Inc said that the outage prevented some customers in "certain regions" from making payments. It apologised for the inconvenience and said that its networks had not been hacked.
A month ago, security guru Bruce Schneier wrote that someone, probably a country, had been testing increasing levels of denial-of-service attacks against unnamed core internet infrastructure providers in what seemed like a test of capability.
Nixon said there was no reason to think a national government was behind Friday's assaults, but attacks carried out on a for-hire basis are famously difficult to attribute.
(Reporting by Joseph Menn in San Francisco, Jim Finkle in Boston and Dustin Volz in Washington. Additional reporting by Eric Auchard in Frankurt, Malathi Nayak in New York, Jeff Mason and Mark Hosenball in Washington, Adrian Croft and Frances Kerry in London; Editing by Bill Trott, Lisa Shumaker and Jonathan Weber)
- Reuters
- wong chee tat :)
Thursday, September 8, 2016
Intel and TPG to Collaborate to Establish McAfee as Leading Independent Cybersecurity Company Valued at $4.2 Billion
Intel and TPG to Collaborate to Establish McAfee as Leading Independent Cybersecurity Company Valued at $4.2 Billion
Intel Corporation and TPG Announce an Agreement Under Which the Two Parties Will Establish a Newly Formed, Jointly-Owned, Independent Cybersecurity Company Called McAfee
Highlights:
- TPG and Intel to jointly invest in spin-out of Intel Security in a transaction valuing the business at $4.2 billion
- Intel to receive $3.1 billion in cash and retain 49 percent stake after completion of the transaction
- TPG to own 51 percent of the new company, which will be named McAfee
- Investment reflects TPG’s confidence in Intel Security’s industry-leading enterprise and consumer businesses, strong market position, and business momentum
- Positions new company as one of the world’s largest pure-play cybersecurity firms
- Intel senior vice president and Intel Security general manager Chris Young and existing management team to lead the new company following transaction close
SANTA CLARA and SAN FRANCISCO, Calif., and FORT WORTH, Texas, Sept. 7, 2016 –Intel Corporation and TPG today announced a definitive agreement under which the two parties will establish a newly formed, jointly-owned, independent cybersecurity company. The new company will be called McAfee following transaction close. TPG will own 51 percent of McAfee and Intel will own 49 percent in a transaction valuing the business at approximately $4.2 billion. TPG is making a $1.1 billion equity investment to help drive growth and enhance focus as a standalone business.
Through this transaction, TPG, a leading global alternative asset firm with demonstrated expertise in growing profitable software companies and carve-out investments, and Intel, a global technology leader that powers the cloud and billions of smart, connected computing devices, will work together to position McAfee as a strong independent company with access to significant financial, operational and technology resources. With the new investment from TPG and continued strategic backing of Intel, the new entity is expected to capitalize on significant global growth opportunities through greater focus and targeted investment.
The new company will be one of the world’s largest pure-play cybersecurity companies. Last year, Intel Security unveiled a new strategy that refocused the business on endpoint and cloud as security control points, as well as actionable threat intelligence, analytics and orchestration. This new strategy allows customers to detect and respond to more threats faster and with fewer resources.
“Security remains important in everything we do at Intel and going forward we will continue to integrate industry-leading security and privacy capabilities in our products from the cloud to billions of smart, connected computing devices,” said Brian Krzanich, CEO of Intel. “As we collaborate with TPG to establish McAfee as an independent company, we will also share in the future success of the business and in the market demand for top-flight security solutions, creating long-term value for McAfee’s customers, partners, employees and Intel’s shareholders. Intel will continue our collaboration with McAfee as we offer safe and secure products to our customers.”
“We believe that McAfee will thrive as an independent company. With TPG’s investment, along with continued support from Intel, McAfee will sharpen its focus and become even more agile in its response to today’s rapidly evolving security sector,” said Jim Coulter, Co-Founder and Co-CEO of TPG. “TPG is excited to partner with Intel and McAfee management to accelerate growth of the business by enhancing its go-to-market strategy and continuing to grow and strengthen its core product offerings.”
“At TPG, we look to partner with both established and emergent leaders in dynamic and growing markets,” said Bryan Taylor, Partner at TPG. “We have long identified the cybersecurity sector, which has experienced strong growth due to the increasing volume and severity of cyberattacks, as one of the most important areas in technology. Given McAfee’s leading global market position, loyal customer base, and trusted technology, we see a compelling opportunity to invest in a highly-strategic platform that is growing consistently and addressing significant and evolving market demand.”
Positioning the New Company for Future Growth
Chris Young will be appointed CEO of the new company upon closing of the transaction. Today he published an open letter to Intel Security’s stakeholders outlining benefits of the transaction and new company.
“As a standalone company supported by these two partners, we will be in an even greater position of strength, committed to being the best provider the cybersecurity industry has ever seen,” Young said. “We will continue to focus on solving the unique demands of customers in the dynamic cybersecurity marketplace, drive innovation that anticipates future market needs, and continue to grow through our strategic priorities.”
Currently, Intel Security’s comprehensive software platform protects more than a quarter of a billion endpoints, secures the footprint for nearly two-thirds of the world’s 2,000 largest companies, detects more than 400,000 new threats each day, and represents more than 7,500 strong of the industry’s most talented professionals. The business has demonstrated strong momentum. Through the first half of this year, Intel Security Group revenue grew 11 percent to $1.1 billion, while operating income grew 391 percent to $182 million. Intel Security also increased total bookings 7 percent per year on a constant currency basis from 2013 to 2015.1
Terms of the Transaction, Financing and Timeline
Under the terms of the agreement, TPG will own 51 percent of a newly-formed cybersecurity company in a multi-step transaction valuing Intel Security at approximately $4.2 billion, based on an equity value of approximately $2.2 billion plus McAfee net debt of approximately $2 billion. The debt initially will be financed by Intel until completion of audited financial statements for McAfee (expected within three to five months of close). The transaction is expected to close in the second quarter of 2017, subject to certain regulatory approvals and customary closing conditions.
About Intel
Intel (NASDAQ: INTC) expands the boundaries of technology to make the most amazing experiences possible. Information about Intel can be found at newsroom.intel.com andintel.com.
About TPG
TPG is a leading global alternative asset firm founded in 1992 with over $70 billion of assets under management and offices in Austin, Beijing, Dallas, Fort Worth, Hong Kong, Houston, Istanbul, London, Luxembourg, Melbourne, Moscow, Mumbai, New York
, San Francisco, São Paulo, Singapore, and Tokyo. TPG’s investment platforms are across a wide range of asset classes, including private equity, growth venture, real estate, credit, and public equity. TPG aims to build dynamic products and options for its investors while also instituting discipline and operational excellence across the investment strategy and performance of its portfolio. For more information, visit http://www.tpg.com/.
, San Francisco, São Paulo, Singapore, and Tokyo. TPG’s investment platforms are across a wide range of asset classes, including private equity, growth venture, real estate, credit, and public equity. TPG aims to build dynamic products and options for its investors while also instituting discipline and operational excellence across the investment strategy and performance of its portfolio. For more information, visit http://www.tpg.com/.
Forward Looking Statements
This document contains forward looking statements related to the proposed transaction between Intel and TPG, including statements regarding the benefits and the timing of the transaction. Forward looking statements are predictions, projections and other statements about future events that are based on current expectations and assumptions and, as a result, are subject to risks and uncertainties. Many factors could cause actual future events to differ materially from the forward-looking statements in this document, including the following, among others: closing of the transaction may not occur or may be delayed; changes in consumer demand; Intel’s ability to successfully separate the Intel Security business and factors affecting McAfee’s ability to operate as a standalone business; the realization of the projected benefits of the proposed transaction; the retention of suppliers, customers and key employees; McAfee’s ability to service and satisfy debt obligations assumed in the transaction; general economic conditions in the regions and industries in which Intel and Intel Security operate; the intensely competitive industries in which Intel and Intel Security operate; and litigation or regulatory matters and other issues that could affect the closing of the transaction.
In addition, please refer to the documents that Intel files with the U.S. Securities and Exchange Commission on Forms 10-K, 10-Q and 8-K. These filings identify and address other important risks and uncertainties that could cause events and results to differ materially from those contained in the forward-looking statements set forth in this document. Readers are cautioned not to put undue reliance on forward-looking statements, and Intel and TPG assume no obligation and do not intend to update these forward-looking statements, whether as a result of new information, future events or otherwise.
1 Excludes bookings for divested businesses (Stonesoft Next Generation Firewall and Enterprise Firewall)
Intel and the Intel logo are trademarks of Intel Corporation in the United States and other countries.
* Other names and brands may be claimed as the property of others.
- wong chee tat :)
Labels:
2016,
buy,
buyers,
cash,
cashflow,
cyber security,
cyberrange,
cyberspace,
Intel,
investors,
job losses,
job seekers,
jobs,
market,
McAfee,
money,
opportunities,
sep,
sophisticated investors,
tpg
Intel and TPG and McAfee
September 7, 2016
Intel Security Stakeholders,
Today, Intel and TPG made an exciting announcement that I want to share with you directly. We unveiled a strategic partnership with the goal of creating one of the largest independent, pure-play cybersecurity companies in the industry. To enable this partnership, we are creating a new corporate entity, to be named McAfee, of which Intel will continue to own 49% and TPG, a leading global alternative asset firm with substantial experience investing in best-in-class technology companies, will own 51%. We will have access to significant financial, operational, and technology resources, enabling us to realize our full potential as a standalone business.
I will continue to lead the organization as CEO of the newly-formed company and couldn’t be more energized about our future and how this transaction moves us forward. We have the right strategy and product portfolio to stay ahead of the adversaries who undermine our digital world. We employ the most talented people steadfast to being our customers’ preferred security partner. And, with this move, we will create the ideal company structure to position McAfee for enhanced focus, innovation and growth. In the end, McAfee will emerge in a position of greater strength, still fully committed to being the best provider in the cybersecurity industry worldwide.
There is no shortage of buzz around cybersecurity these days. Those of us in the industry, and those defending their businesses and families, have the unique privilege of standing on the good side of a fight that is too important to lose. With that in mind, I’m convinced this move marks the beginning of a new future for our customers, partners, and employees:
- For our corporate and government customers, you will benefit from a focused, agile and independent provider further committed to protecting you, recognizing that you require simplicity in your security environment as much as you do effectiveness. With McAfee, you will get a proven player with a leading portfolio – focusing on endpoint and cloud as security control points, combined with actionable threat intelligence, analytics and orchestration – allowing you to detect and respond to more threats faster and with fewer resources. And, you will have a provider with a management team committed to a strategy unveiled nearly a year ago. We are resolute in delivering our product roadmaps, and this new partnership and pure-play status allows us to invest more and execute even faster to enhance our product and services offerings on your behalf.
- For our consumers, who trust us each day to protect the most sensitive and valuable aspects of your digital life, we are as committed as ever to defending you against those meaning you harm. You will have peace of mind being protected by a leader with a history of identifying current and emerging threats – one that will work tirelessly to safeguard you in a virtual world. McAfee will continue to innovate on your behalf, bringing you cybersecurity solutions to protect you across multiple devices.
- For our partners, you will be able to confidently represent one of the most comprehensive, leading portfolios in the industry. As a pure-play provider, McAfee will accelerate the rate of innovation in delivering an integrated portfolio that is increasingly automated and orchestrated. And, with the investment by Intel, you will continue to benefit from Intel’s technology leadership. Rest assured that McAfee will continue to stand behind you, alongside our joint customers, in delivering solutions across the entirety of the threat defense lifecycle.
- Our employees are our most important strategic asset. We have a unique opportunity to create a new future by joining together in architecting the best cybersecurity company in our industry. Today’s announcement validates the strategy we embarked upon last year, and signals a goal of achieving our shared company vision and enhancing our product portfolio for our customers with committed investment, continuity and focus. We are united in our noble cause of protecting consumers, corporations and governments.
TPG is a seasoned technology investor that was attracted to our current momentum and long-term potential. Together, they and Intel are committed to building the best cybersecurity company in the industry – because our customers deserve no less.
McAfee will be that company. Today, we already protect more than a quarter of a billion endpoints, secure the footprint for nearly two-thirds of the world’s 2,000 largest companies, defend more than 200 million consumers, detect more than 400,000 new threats each day and represent more than 7,500 strong of the industry’s most talented cybersecurity professionals. We will deliver even more in the future.
Our customers want the reassurance that our strategy has not changed. It hasn’t. Our partners need to know our commitment will not falter. It won’t. Our employees want to know you are part of a company positioned to thrive. You are.
More details will be available once the transaction closes. I am excited to work with each of you to write the next chapter of the McAfee story. Until then, I want to thank each of you for standing with McAfee and for entrusting us as your cybersecurity partner or provider of choice.
Our future starts now. And the best is yet to come.
Christopher Young
Senior Vice President and General Manager
Intel Security Group
Intel Security Group
- wong chee tat :)
Labels:
2016,
buy,
buyers,
cash,
cashflow,
cyber security,
cyberrange,
cyberspace,
Intel,
investors,
job losses,
job seekers,
jobs,
market,
McAfee,
money,
opportunities,
sep,
sophisticated investors,
tpg
Tuesday, August 23, 2016
UNSEALING THE DEAL: CYBER THREATS TO MERGERS AND ACQUISITIONS PERSIST IN A HOT MARKET
UNSEALING THE DEAL: CYBER THREATS TO MERGERS AND ACQUISITIONS PERSIST IN A HOT MARKET
August 23, 2016 | by Holly Ridgeway, FireEye Threat Intelligence | Threat Research, Threat Intelligence
Risks Posed by Sensitive Corporate Communications, Broadened Attack Surface
In 2015, a record $5 trillion dollars was tied up in mergers and acquisitions (M&A) deals, according to JP Morgan. So far, mega deals in 2016 include Microsoft’s purchase of LinkedIn, Shire’s acquisition of Baxalta, and Marriott’s acquisition of Starwood. These market-moving events often involve a massive expenditure of capital and are largely conducted in secret to comply with legal requirements, making them attractive targets for cybercriminals and nation-state threat groups alike. Threat actors are primarily driven by three motives related to M&A activity:
Stealing non-public information leading up to the deal’s announcement for future financial gain.
Exploiting sensitive financial information generated during the M&A process.
Exploiting the increased attack surface created by companies combining their operations.
Additionally, acquisition targets may be compromised prior to the M&A for reasons wholly unrelated to the transaction. Enterprises should be especially alert for malicious cyber activity before, during, and shortly after M&A-related activities, ensuring that due-diligence processes incorporate assessments of each party’s cyber security practices.
Trove of Documents to Exploit Capital Markets
M&A activity generates significant amounts of sensitive corporate communications, which cyber criminals may attempt to obtain and exploit for financial gain. For example, cyber criminals could attempt to gather data about a company's operations, financial status or future plans, which could then be used in stock market trades. To obtain such sensitive information, attackers can target the companies directly involved in the M&A activity themselves or other organizations involved in the deal, such as law firms and PR agencies.
The U.S. Securities and Exchange Commission (SEC) in 2015 announced that since at least 2010, two Ukrainian cyber criminals breached multiple newswire services and distributed pre-release information to a rogue network of international traders and hedge fund managers.
In 2013 and 2014, a group of cyber criminals known as FIN4 sought to acquire information about M&A discussions in order to game the stock market. The group frequently used M&A and SEC-themed lures with Visual Basic for Applications (VBA) macros implemented to steal the usernames and passwords of key individuals. Many of FIN4’s lures were apparently stolen documents from actual deal discussions that the group then weaponized and sent to individuals directly involved in the deal. FIN4 typically included links to fake Outlook Web App (OWA) login pages designed to capture the user’s credentials. Once equipped with the credentials, FIN4 then obtained access to real-time email communications and presumably insight into potential deals and their timing.
Seeking Insights to Gain the Upper Hand in Negotiations
One side involved in M&A negotiations could use cyber espionage to acquire sensitive information about a deal counterparty in an attempt to obtain more favorable terms. Based on past threat actor activity, we have observed multiple China-based threat actors breach companies to observed this type of activity in sizeable deals involving Chinese state-owned enterprises.
High tech companies in particular face an evolving cyber risk as Chinese interests advance toward acquisition of technology and expertise that will sustain the country’s economic growth through a shift to an economy built on knowledge-based products and services. During the past decade, flush with cash and often with state backing, Chinese companies have snatched up well-known Western companies in industries ranging from agriculture to energy to consumer products. The Wall Street Journal reported that as of May 2016, Chinese companies have struck over $110.8 billion in overseas deals, surpassing the $106.8 billion in deals done in 2015, despite a slowdown in the Chinese economy.
As recently as late 2015, we have observed several likely China-based threat groups targeting companies engaged in M&A-related activity. At least four different China-based APT groups conducted computer network intrusions that we believe were primarily motivated by the targeted companies’ involvement in an acquisition.
In 2015, Mandiant conducted a compromise assessment for a business services company. We identified two periods of activity by the China-based threat group APT8 within the network, the most recent of which coincided with the victim company's participation in acquisition negotiations. Although our visibility into APT8's operations was limited, the threat group possibly sought information pertaining to the negotiation and acquisition itself, based on the timing in which APT8 resumed their activity within the network.
New Companies, New Attack Surfaces
Mergers and acquisitions often result in an increased attack surface for the companies involved. As two or more companies integrate their IT assets, a group that has compromised one company could potentially use that access to compromise the other(s). For instance, the Australian telecom firm Telstra in 2015 announced that the networks of a recently acquired subsidiary, Pacnet, were exploited.
Although the most obvious example of the increased attack surface issue is when M&A activity causes companies to combine their networks, it can also include factors such as one company’s particular susceptibility to social-networking attacks or vulnerabilities in products produced by one of the companies. In other words, strong security practices at one company can be obviated by poor practices at the other.
This threat is likely elevated during and immediately after a merger or acquisition, since IT employees at the purchasing company may not have had time to analyze the security posture of the purchased company, or the combined staffs are unable to comprehensively monitor the entirety of the newly combined network. Mergers and acquisitions also generally increase the opportunities for “lateral compromise” by targeting trusted relationships (i.e., the relationship between the companies involved in the M&A activity). When a well protected network recognizes a less secure network as trusted, the overall security posture of the combined network is lowered, allowing intruders to gain access by exploiting hastily-granted trust between systems.
Mandiant has observed instances where APT actors were able to regain a foothold in an organization’s network following remediation by compromising the network of an affiliate. Actors targeting companies during M&A activity could use similar tactics to move laterally from one company to another.
An example of this is when Mandiant performed an incident response investigation for Company A, where we identified the presence of several advanced threat actors. After remediating Company A’s networks, an APT group attempted to re-compromise the network through a sister organization (Company B), which had also been previously compromised. Although this effort failed, a different APT group was able to regain access to Company A’s systems through a strategic web compromise embedded on Company B’s website. Our investigation of the sister company’s network revealed that the vast majority of stolen data there pertained to the network infrastructure linking the organizations.
Another example occurred at Company C, where we identified four APT groups active in a network. Analysis about the timing and behavior of at least one of these groups suggested that they were able to leverage their previously attained access at Company D (a sister organization) to access Company C’s network. During our investigation at Company D, we discovered at least two threat groups, with activity dating back three years earlier. We believe these actors used information harvested from Company D’s network to help exploit Company C in a subsequent operation.
Mitigation
Business leaders responsible for M&A business strategy should be aware that threat actors often target companies engaged in mergers and acquisitions, and that malicious activities such as phishing attacks will likely increase during such periods. Additionally, a data breach or severe security posture weaknesses could negate the business strategy of acquisition due to the often-high cost of fixing weaknesses or conducting incident response. Technology risk should be evaluated and incorporated into the overall business risk strategy before an M&A transaction is completed. In addition, companies engaged in M&A should ensure that an examination of cyber security is included as a key component of the due diligence process.
Today cyber due diligence is oftentimes performed superficially and as an afterthought. This examination should include details of the company’s security capabilities such as data safeguards, access controls, threat detection, incident response and infrastructure security controls, the threat landscape of the organization, any records of past attacks, and any underground actors known to be particularly interested in targeting the company. Allowing sufficient time (four to six weeks) to perform an actual compromise assessment on the sellers’ infrastructure will provide the optimal visibility into the security posture of the acquisition.
When sufficient time is provided and cyber due diligence is conducted, senior executives at the acquiring organization will understand the business threats and technology risk posed by the acquisition target, enabling them to incorporate this information into the overall enterprise risk picture for informed decision-making. In the majority of transactions, the decision to move forward with the acquisition will still continue; however, senior executives will be better equipped to make informed decisions about:
Deal value
Terms
Cost of remediation of security weaknesses or breach response
Return on investment of the acquisition
Purchase of a cyber insurance to transfer risk
Probability and cost of future litigation resulting from a breach
When to Start Cyber Security Due Diligence
It’s important for all parties to a transaction to work with their respective counsel to ensure any cyber due diligence activities are performed in a compliant manner (e.g., to avoid creating privacy issues) and in a way that helps preserve any available legal privileges.
Cyber security should be planned for like any other due diligence – as early as possible. Because of some fairly specific requirements to ensure the quality of cyber security due diligence, some language may need to be inserted into agreement documents such as a Letter of Intent (LOI). This will enable key components of a cyber security due diligence, such as network monitoring.
M&A due diligence teams sometimes contain information technology (IT) subject matter experts (SMEs) who are occasionally asked to also provide an opinion on cyber security posture; however, cyber security is a specialized field, and if security expertise is not available on staff, due diligence providers should start planning to retain outside resources.
What Cyber Security Due Diligence Should Be
The following are factors that should be incorporated into effective cyber security due diligence planning. Note that M&As can vary widely in terms of ramp-up time. Some allow for a very short due diligence effort, while longer deals can afford months to assess risk. Business decisions control this pace, not the due diligence team – therefore it is important to have relatively quick and lightweight cyber due diligence options as well as longer, more in-depth approaches.
Quick Diligence
If the window for due diligence is short (e.g., 1-2 weeks), there is still substantial cyber security due diligence that can be accomplished to provide a high-level view of the risk levels of the seller’s environment. A week provides time for cyber security experts to conduct documentation review and interviews with seller staff, which they then analyze in a focused risk framework. The product of this activity should be a quantified risk assessment across important cyber security domains (e.g., data safeguarding, infrastructure security, and others) that results in a brief, easy-to-understand report on risk and general recommendations for the buyer.
Even minimal cyber security due diligence should have a technical component to provide an objective view of the health of the seller’s security posture. One of the most important aspects of a technical assessment is creating a historical scorecard going back in time: Have the seller’s computers been compromised in the past, and what was the character of those breaches (advanced and persistent, commodity, insider, financial fraud, etc.)? The Freshfields survey discovered 90% of respondents believed that a past breach could reduce the value of a deal.
Also important is a current snapshot: detecting malicious activity (or the lack of such activity) from the seller provides insight into the overall security posture and types of possible intruders already in place. This information needs to be derived and analyzed in a relatively short time frame. With this kind of analysis, the buyer already can act knowledgably and prevent major missteps.
In-Depth Due Diligence
If more time is available, more detailed and granular cyber security due diligence is possible. In addition to a risk assessment conducted by cyber security analysts, software agents can be deployed in the seller’s network to report on the state of the endpoints.
Network monitoring can examine traffic to and from the network for a period of time to collect very detailed information on the state of the organization’s cyber security and what compromises are already happening, or have already happened. This allows the buyer to know the seller’s environment inside and out from a real-world risk perspective, and would provide both the high-level view needed to inform decisions and granular detail to estimate remediation costs.
Only with due diligence can risk be incorporated in planning, with various planned costs and benefits. Without due diligence, there are only unexpected costs and reputational impacts.
Post-Acquisition Activities
Information gathered during due diligence can be further used to guide post-acquisition activities.
Integration
A fairly common follow-on activity, particularly with mergers, is integration of the two companies’ IT infrastructure. In the long run, this should reduce costs and ease management; however, in the short-term it can create its own set of problems and become a long-term effort.
One of the first questions to answer is: what can be trusted? Is it safe for the buyer to connect to certain acquired systems? Can two-way trust relationships be established? All of these depend on assessing the security of both the overall environment and specific systems. Cyber security due diligence provides a good start down this road, and can allow for a level of effort and cost estimates to be made and included in IT planning.
The Future Has Already Been Here
The impact of adverse cyber security events has been felt by businesses for some time, and paying a little attention to the news gives some sense of the scale of the challenges that have emerged as even local businesses become exploitable by global criminals. Cyber security risk is not science fiction, even though it has essentially been treated as science fiction by being left out of M&A processes. Acquiring companies and due diligence practitioners must now catch up to the reality of the costs and risks that cyber security issues create, and the benefits that cyber security due diligence can bring. Doing so will eventually separate successes from the also-rans.
For more information on how Mandiant Consulting can help before, during and after a merger or acquisition, visit Fireeye.com/services.html.
- wong chee tat :)
August 23, 2016 | by Holly Ridgeway, FireEye Threat Intelligence | Threat Research, Threat Intelligence
Risks Posed by Sensitive Corporate Communications, Broadened Attack Surface
In 2015, a record $5 trillion dollars was tied up in mergers and acquisitions (M&A) deals, according to JP Morgan. So far, mega deals in 2016 include Microsoft’s purchase of LinkedIn, Shire’s acquisition of Baxalta, and Marriott’s acquisition of Starwood. These market-moving events often involve a massive expenditure of capital and are largely conducted in secret to comply with legal requirements, making them attractive targets for cybercriminals and nation-state threat groups alike. Threat actors are primarily driven by three motives related to M&A activity:
Stealing non-public information leading up to the deal’s announcement for future financial gain.
Exploiting sensitive financial information generated during the M&A process.
Exploiting the increased attack surface created by companies combining their operations.
Additionally, acquisition targets may be compromised prior to the M&A for reasons wholly unrelated to the transaction. Enterprises should be especially alert for malicious cyber activity before, during, and shortly after M&A-related activities, ensuring that due-diligence processes incorporate assessments of each party’s cyber security practices.
Trove of Documents to Exploit Capital Markets
M&A activity generates significant amounts of sensitive corporate communications, which cyber criminals may attempt to obtain and exploit for financial gain. For example, cyber criminals could attempt to gather data about a company's operations, financial status or future plans, which could then be used in stock market trades. To obtain such sensitive information, attackers can target the companies directly involved in the M&A activity themselves or other organizations involved in the deal, such as law firms and PR agencies.
The U.S. Securities and Exchange Commission (SEC) in 2015 announced that since at least 2010, two Ukrainian cyber criminals breached multiple newswire services and distributed pre-release information to a rogue network of international traders and hedge fund managers.
In 2013 and 2014, a group of cyber criminals known as FIN4 sought to acquire information about M&A discussions in order to game the stock market. The group frequently used M&A and SEC-themed lures with Visual Basic for Applications (VBA) macros implemented to steal the usernames and passwords of key individuals. Many of FIN4’s lures were apparently stolen documents from actual deal discussions that the group then weaponized and sent to individuals directly involved in the deal. FIN4 typically included links to fake Outlook Web App (OWA) login pages designed to capture the user’s credentials. Once equipped with the credentials, FIN4 then obtained access to real-time email communications and presumably insight into potential deals and their timing.
Seeking Insights to Gain the Upper Hand in Negotiations
One side involved in M&A negotiations could use cyber espionage to acquire sensitive information about a deal counterparty in an attempt to obtain more favorable terms. Based on past threat actor activity, we have observed multiple China-based threat actors breach companies to observed this type of activity in sizeable deals involving Chinese state-owned enterprises.
High tech companies in particular face an evolving cyber risk as Chinese interests advance toward acquisition of technology and expertise that will sustain the country’s economic growth through a shift to an economy built on knowledge-based products and services. During the past decade, flush with cash and often with state backing, Chinese companies have snatched up well-known Western companies in industries ranging from agriculture to energy to consumer products. The Wall Street Journal reported that as of May 2016, Chinese companies have struck over $110.8 billion in overseas deals, surpassing the $106.8 billion in deals done in 2015, despite a slowdown in the Chinese economy.
As recently as late 2015, we have observed several likely China-based threat groups targeting companies engaged in M&A-related activity. At least four different China-based APT groups conducted computer network intrusions that we believe were primarily motivated by the targeted companies’ involvement in an acquisition.
In 2015, Mandiant conducted a compromise assessment for a business services company. We identified two periods of activity by the China-based threat group APT8 within the network, the most recent of which coincided with the victim company's participation in acquisition negotiations. Although our visibility into APT8's operations was limited, the threat group possibly sought information pertaining to the negotiation and acquisition itself, based on the timing in which APT8 resumed their activity within the network.
New Companies, New Attack Surfaces
Mergers and acquisitions often result in an increased attack surface for the companies involved. As two or more companies integrate their IT assets, a group that has compromised one company could potentially use that access to compromise the other(s). For instance, the Australian telecom firm Telstra in 2015 announced that the networks of a recently acquired subsidiary, Pacnet, were exploited.
Although the most obvious example of the increased attack surface issue is when M&A activity causes companies to combine their networks, it can also include factors such as one company’s particular susceptibility to social-networking attacks or vulnerabilities in products produced by one of the companies. In other words, strong security practices at one company can be obviated by poor practices at the other.
This threat is likely elevated during and immediately after a merger or acquisition, since IT employees at the purchasing company may not have had time to analyze the security posture of the purchased company, or the combined staffs are unable to comprehensively monitor the entirety of the newly combined network. Mergers and acquisitions also generally increase the opportunities for “lateral compromise” by targeting trusted relationships (i.e., the relationship between the companies involved in the M&A activity). When a well protected network recognizes a less secure network as trusted, the overall security posture of the combined network is lowered, allowing intruders to gain access by exploiting hastily-granted trust between systems.
Mandiant has observed instances where APT actors were able to regain a foothold in an organization’s network following remediation by compromising the network of an affiliate. Actors targeting companies during M&A activity could use similar tactics to move laterally from one company to another.
An example of this is when Mandiant performed an incident response investigation for Company A, where we identified the presence of several advanced threat actors. After remediating Company A’s networks, an APT group attempted to re-compromise the network through a sister organization (Company B), which had also been previously compromised. Although this effort failed, a different APT group was able to regain access to Company A’s systems through a strategic web compromise embedded on Company B’s website. Our investigation of the sister company’s network revealed that the vast majority of stolen data there pertained to the network infrastructure linking the organizations.
Another example occurred at Company C, where we identified four APT groups active in a network. Analysis about the timing and behavior of at least one of these groups suggested that they were able to leverage their previously attained access at Company D (a sister organization) to access Company C’s network. During our investigation at Company D, we discovered at least two threat groups, with activity dating back three years earlier. We believe these actors used information harvested from Company D’s network to help exploit Company C in a subsequent operation.
Mitigation
Business leaders responsible for M&A business strategy should be aware that threat actors often target companies engaged in mergers and acquisitions, and that malicious activities such as phishing attacks will likely increase during such periods. Additionally, a data breach or severe security posture weaknesses could negate the business strategy of acquisition due to the often-high cost of fixing weaknesses or conducting incident response. Technology risk should be evaluated and incorporated into the overall business risk strategy before an M&A transaction is completed. In addition, companies engaged in M&A should ensure that an examination of cyber security is included as a key component of the due diligence process.
Today cyber due diligence is oftentimes performed superficially and as an afterthought. This examination should include details of the company’s security capabilities such as data safeguards, access controls, threat detection, incident response and infrastructure security controls, the threat landscape of the organization, any records of past attacks, and any underground actors known to be particularly interested in targeting the company. Allowing sufficient time (four to six weeks) to perform an actual compromise assessment on the sellers’ infrastructure will provide the optimal visibility into the security posture of the acquisition.
When sufficient time is provided and cyber due diligence is conducted, senior executives at the acquiring organization will understand the business threats and technology risk posed by the acquisition target, enabling them to incorporate this information into the overall enterprise risk picture for informed decision-making. In the majority of transactions, the decision to move forward with the acquisition will still continue; however, senior executives will be better equipped to make informed decisions about:
Deal value
Terms
Cost of remediation of security weaknesses or breach response
Return on investment of the acquisition
Purchase of a cyber insurance to transfer risk
Probability and cost of future litigation resulting from a breach
When to Start Cyber Security Due Diligence
It’s important for all parties to a transaction to work with their respective counsel to ensure any cyber due diligence activities are performed in a compliant manner (e.g., to avoid creating privacy issues) and in a way that helps preserve any available legal privileges.
Cyber security should be planned for like any other due diligence – as early as possible. Because of some fairly specific requirements to ensure the quality of cyber security due diligence, some language may need to be inserted into agreement documents such as a Letter of Intent (LOI). This will enable key components of a cyber security due diligence, such as network monitoring.
M&A due diligence teams sometimes contain information technology (IT) subject matter experts (SMEs) who are occasionally asked to also provide an opinion on cyber security posture; however, cyber security is a specialized field, and if security expertise is not available on staff, due diligence providers should start planning to retain outside resources.
What Cyber Security Due Diligence Should Be
The following are factors that should be incorporated into effective cyber security due diligence planning. Note that M&As can vary widely in terms of ramp-up time. Some allow for a very short due diligence effort, while longer deals can afford months to assess risk. Business decisions control this pace, not the due diligence team – therefore it is important to have relatively quick and lightweight cyber due diligence options as well as longer, more in-depth approaches.
Quick Diligence
If the window for due diligence is short (e.g., 1-2 weeks), there is still substantial cyber security due diligence that can be accomplished to provide a high-level view of the risk levels of the seller’s environment. A week provides time for cyber security experts to conduct documentation review and interviews with seller staff, which they then analyze in a focused risk framework. The product of this activity should be a quantified risk assessment across important cyber security domains (e.g., data safeguarding, infrastructure security, and others) that results in a brief, easy-to-understand report on risk and general recommendations for the buyer.
Even minimal cyber security due diligence should have a technical component to provide an objective view of the health of the seller’s security posture. One of the most important aspects of a technical assessment is creating a historical scorecard going back in time: Have the seller’s computers been compromised in the past, and what was the character of those breaches (advanced and persistent, commodity, insider, financial fraud, etc.)? The Freshfields survey discovered 90% of respondents believed that a past breach could reduce the value of a deal.
Also important is a current snapshot: detecting malicious activity (or the lack of such activity) from the seller provides insight into the overall security posture and types of possible intruders already in place. This information needs to be derived and analyzed in a relatively short time frame. With this kind of analysis, the buyer already can act knowledgably and prevent major missteps.
In-Depth Due Diligence
If more time is available, more detailed and granular cyber security due diligence is possible. In addition to a risk assessment conducted by cyber security analysts, software agents can be deployed in the seller’s network to report on the state of the endpoints.
Network monitoring can examine traffic to and from the network for a period of time to collect very detailed information on the state of the organization’s cyber security and what compromises are already happening, or have already happened. This allows the buyer to know the seller’s environment inside and out from a real-world risk perspective, and would provide both the high-level view needed to inform decisions and granular detail to estimate remediation costs.
Only with due diligence can risk be incorporated in planning, with various planned costs and benefits. Without due diligence, there are only unexpected costs and reputational impacts.
Post-Acquisition Activities
Information gathered during due diligence can be further used to guide post-acquisition activities.
Integration
A fairly common follow-on activity, particularly with mergers, is integration of the two companies’ IT infrastructure. In the long run, this should reduce costs and ease management; however, in the short-term it can create its own set of problems and become a long-term effort.
One of the first questions to answer is: what can be trusted? Is it safe for the buyer to connect to certain acquired systems? Can two-way trust relationships be established? All of these depend on assessing the security of both the overall environment and specific systems. Cyber security due diligence provides a good start down this road, and can allow for a level of effort and cost estimates to be made and included in IT planning.
The Future Has Already Been Here
The impact of adverse cyber security events has been felt by businesses for some time, and paying a little attention to the news gives some sense of the scale of the challenges that have emerged as even local businesses become exploitable by global criminals. Cyber security risk is not science fiction, even though it has essentially been treated as science fiction by being left out of M&A processes. Acquiring companies and due diligence practitioners must now catch up to the reality of the costs and risks that cyber security issues create, and the benefits that cyber security due diligence can bring. Doing so will eventually separate successes from the also-rans.
For more information on how Mandiant Consulting can help before, during and after a merger or acquisition, visit Fireeye.com/services.html.
- wong chee tat :)
Labels:
2016,
aug,
august,
cyber security,
cyberrange,
cyberspace,
market,
opportunities,
software
Wednesday, July 20, 2016
National Cybercrime Action Plan to step up fight against online crime: Shanmugam
National Cybercrime Action Plan to step up fight against online crime: Shanmugam
By Kimberly Spykerman, News 5 Posted 20 Jul 2016 18:41 Updated 20 Jul 2016 22:57
SINGAPORE: Singapore will do more in the battle against online crime through a National Cybercrime Action Plan, Home Affairs Minister and Law Minister K Shanmugam announced on Wednesday (Jul 20).
Speaking at a conference, Mr Shanmugam pointed out that the plan signifies a fundamental relook at the way cybercrime is tackled, and recognised the sea change cybercrime will bring about in society.
"Cybercrime is seen, and rightly identified, as a growing threat. It doesn't recognise national boundaries. They hide behind, they are in the shadows, and they strike. And the scale and the speed with which they can strike is such that it can cause tremendous damage," he said.
Cybercrimes around the world have been increasing, he added.
Mr Shanmugam also pointed out that cyberspace is changing the complexion of crimes all over the world. In the UK, the number of crimes that involved a computer exceeded physical crimes in 2015. In the same year in Singapore, the number of cases under the Computer Misuse and Cybersecurity Act increased by more than 40 per cent compared to 2014.
FOUR KEY PRIORITIES FOR FOUR KEY PRINCIPLES
Singapore will do its part through its action plan that is underpinned by four key principles - prevention, a quick, strong response to incidents of cybercrime, effective laws and close partnerships.
These will translate to four key priorities in the action plan, said Mr Shanmugam.
The first priority is to educate and empower the public to stay safe in cyberspace.
Prevention is key, said Mr Shanmugam, citing the police’s efforts to educate the public through ads, Crimewatch broadcasts, social media and other outreach avenues.
There will also be a special focus on vulnerable groups like the elderly and children. In this area, the police will work with schools and NGOs to raise awareness among these groups.
The police will also transform its existing Scam Alert website into a one-stop self-help portal, where people can get information on the latest modus operandi of cybercriminals, hear from other people’s experiences and report cases.
Secondly, authorities will enhance capabilities to fight cybercrime.
Mr Shanmugam noted that a Cybercrime Command was established in December 2015. It will carry out tasks such as analysing new methods used by cybercriminals, which can then be used to shape crime prevention messages.
The Home Affairs Ministry will also expand the curriculum of the Cyber Security Lab - which is a hands-on training facility - to cover topics like cyber-security fundamentals, digital forensics and malware analysis.
Third, laws will be strengthened to respond to the transnational nature of cybercrimes and the evolving tactics of such criminals. He added that existing laws will be looked at, to ensure they remain relevant even as traditional crimes shift online.
"What happens in the real world will have to be replicated in the virtual world. And we have to develop the tools to make sure they're updated for that," said Mr Shanmugam.
Lastly, local and international partnerships will be established.
Singapore has worked with the Chinese authorities to bust a spate of credit-for-sex scams and plans to support fellow ASEAN member states in developing cybercrime capabilities. An Institute of Safety and Security Studies - where ASEAN member states can also get training - has been established here.
Singapore is also home to Interpol's Global Complex for Innovation, which has a strong focus on cybercrime.
Mr Shanmugam emphasised that the Government will work closely with partners across all sectors to share knowledge and expertise, as well as to build capability.
Singapore, he added, is committed to supporting the global fight against cybercrime, and can contribute in the area of capability development - both regionally and internationally.
"COORDINATED APPROACH IS KEY"
Separately, Interpol chief Jurgen Stock said Singapore - as a hyper-connected, well-developed country - provides opportunities for cybercriminals. He added that mobile devices are set to become bigger targets, with more people using them to carry out important tasks such as banking transactions.
Mr Stock, who is the secretary-general of Interpol, said that is why having a coordinated approach is key to deterring cybercriminals.
"I think Singapore, with a new plan, provides a lot of measures to protect the system," he said. "And this is so important, and we have to understand that we have to build strong partnerships."
"The public has to play its role in protecting their own systems. So we all have to be aware of the way we use our smartphones, the way we use our computers. And we have to protect our critical infrastructure and our societies, and that is a huge task also for the lawmakers," he added.
- CNA/dl
- wong chee tat :)
By Kimberly Spykerman, News 5 Posted 20 Jul 2016 18:41 Updated 20 Jul 2016 22:57
SINGAPORE: Singapore will do more in the battle against online crime through a National Cybercrime Action Plan, Home Affairs Minister and Law Minister K Shanmugam announced on Wednesday (Jul 20).
Speaking at a conference, Mr Shanmugam pointed out that the plan signifies a fundamental relook at the way cybercrime is tackled, and recognised the sea change cybercrime will bring about in society.
"Cybercrime is seen, and rightly identified, as a growing threat. It doesn't recognise national boundaries. They hide behind, they are in the shadows, and they strike. And the scale and the speed with which they can strike is such that it can cause tremendous damage," he said.
Cybercrimes around the world have been increasing, he added.
Mr Shanmugam also pointed out that cyberspace is changing the complexion of crimes all over the world. In the UK, the number of crimes that involved a computer exceeded physical crimes in 2015. In the same year in Singapore, the number of cases under the Computer Misuse and Cybersecurity Act increased by more than 40 per cent compared to 2014.
FOUR KEY PRIORITIES FOR FOUR KEY PRINCIPLES
Singapore will do its part through its action plan that is underpinned by four key principles - prevention, a quick, strong response to incidents of cybercrime, effective laws and close partnerships.
These will translate to four key priorities in the action plan, said Mr Shanmugam.
The first priority is to educate and empower the public to stay safe in cyberspace.
Prevention is key, said Mr Shanmugam, citing the police’s efforts to educate the public through ads, Crimewatch broadcasts, social media and other outreach avenues.
There will also be a special focus on vulnerable groups like the elderly and children. In this area, the police will work with schools and NGOs to raise awareness among these groups.
The police will also transform its existing Scam Alert website into a one-stop self-help portal, where people can get information on the latest modus operandi of cybercriminals, hear from other people’s experiences and report cases.
Secondly, authorities will enhance capabilities to fight cybercrime.
Mr Shanmugam noted that a Cybercrime Command was established in December 2015. It will carry out tasks such as analysing new methods used by cybercriminals, which can then be used to shape crime prevention messages.
The Home Affairs Ministry will also expand the curriculum of the Cyber Security Lab - which is a hands-on training facility - to cover topics like cyber-security fundamentals, digital forensics and malware analysis.
Third, laws will be strengthened to respond to the transnational nature of cybercrimes and the evolving tactics of such criminals. He added that existing laws will be looked at, to ensure they remain relevant even as traditional crimes shift online.
"What happens in the real world will have to be replicated in the virtual world. And we have to develop the tools to make sure they're updated for that," said Mr Shanmugam.
Lastly, local and international partnerships will be established.
Singapore has worked with the Chinese authorities to bust a spate of credit-for-sex scams and plans to support fellow ASEAN member states in developing cybercrime capabilities. An Institute of Safety and Security Studies - where ASEAN member states can also get training - has been established here.
Singapore is also home to Interpol's Global Complex for Innovation, which has a strong focus on cybercrime.
Mr Shanmugam emphasised that the Government will work closely with partners across all sectors to share knowledge and expertise, as well as to build capability.
Singapore, he added, is committed to supporting the global fight against cybercrime, and can contribute in the area of capability development - both regionally and internationally.
"COORDINATED APPROACH IS KEY"
Separately, Interpol chief Jurgen Stock said Singapore - as a hyper-connected, well-developed country - provides opportunities for cybercriminals. He added that mobile devices are set to become bigger targets, with more people using them to carry out important tasks such as banking transactions.
Mr Stock, who is the secretary-general of Interpol, said that is why having a coordinated approach is key to deterring cybercriminals.
"I think Singapore, with a new plan, provides a lot of measures to protect the system," he said. "And this is so important, and we have to understand that we have to build strong partnerships."
"The public has to play its role in protecting their own systems. So we all have to be aware of the way we use our smartphones, the way we use our computers. And we have to protect our critical infrastructure and our societies, and that is a huge task also for the lawmakers," he added.
- CNA/dl
- wong chee tat :)
Monday, June 13, 2016
Opportunities for insurers to cover risks from cyber attacks, natural disasters: Tharman
Opportunities for insurers to cover risks from cyber attacks, natural disasters: Tharman
Deputy Prime Minister Tharman Shanmugaratnam cites growth areas in the region that insurers can tap, including providing insurance solutions for cyber and natural disaster risks as well as investing in infrastructure.
By Nicole Tan
Posted 13 Jun 2016 21:54 Updated 13 Jun 2016 22:06
SINGAPORE: There are opportunities for insurers in financing infrastructure and providing insurance for cyber attacks and natural disasters, despite the challenge of persistently low interest rates, said Deputy Prime Minister and Coordinating Minister for Economic and Social Policies Tharman Shanmugaratnam.
He was speaking at the International Insurance Society Global Insurance Forum on Monday (Jun 13).
Mr Tharman cited growth areas in the region that insurers can tap, including providing insurance solutions for cyber and natural disaster risks, as well as investing in infrastructure.
To enable long-term investments, such as for infrastructure, Mr Tharman said the Monetary Authority of Singapore is seeking to modify its risk-based capital framework for insurers. He said the next public consultation on this will be held at the end of the month.
Mr Tharman also noted that the economic cost of natural disasters is growing but that the take-up of catastrophe insurance in Asia has been "woefully low". The Deputy Prime Minister pointed to a data gap: "The industry needs good data on the frequency, location and economic impact of natural disasters, so that insurers and reinsurers can price risks adequately. So we have had a limited supply of insurance coverage, that has itself led to higher cost of protection, which in turn discourages demand for insurance against catastrophe risks."
Likewise, Mr Tharman noted that the data needed for the efficient underwriting of cyber risk is "weak". He said: "We need to strengthen collaboration between the industry, government and academia to build reliable databases and analytical tools to enable the efficient underwriting of cyber risk."
ACTIVE INVESTMENT MANAGEMENT 'NOT ALL IT HAS BEEN CRACKED UP TO BE'
As populations age, individuals need to save more for a longer retirement. Meanwhile, slower economic growth is weighing on investment. Mr Tharman said higher savings and lower investment suggest that long-term real interest rates are likely to stay low for quite some time to come. He added that this poses a challenge for insurance and pension funds.
He said: “It hits you on both your assets and your liabilities. It means a lower return on your assets. And it pushes up the value of liabilities because the discount rate has gone down. It is not a temporary challenge but a long-term challenge.
"As life expectancy goes up, liabilities will be pushed out further, and the gap in maturity between your liabilities and your assets is likely to grow. This mismatch in durations, together with low interest rates, means we have a growing problem."
Going forward, Mr Tharman said fundamental reforms are needed to address the challenges, such as making the workplace more attractive to older employees.
As for the finance industry, he said there should be a shift towards passive investment management, away from active management which has proven costly for ordinary savers.
Mr Tharman said: “Active management is not all it has been cracked up to be: it has not proven its worth for most ordinary savers preparing for their retirement. We do have to move towards a system, in a whole range of countries, of helping people save for the long term through passive investment funds, and pool savings to avoid fragmentation and excessive marketing costs.”
- CNA/ms
- wong chee tat :)
Deputy Prime Minister Tharman Shanmugaratnam cites growth areas in the region that insurers can tap, including providing insurance solutions for cyber and natural disaster risks as well as investing in infrastructure.
By Nicole Tan
Posted 13 Jun 2016 21:54 Updated 13 Jun 2016 22:06
SINGAPORE: There are opportunities for insurers in financing infrastructure and providing insurance for cyber attacks and natural disasters, despite the challenge of persistently low interest rates, said Deputy Prime Minister and Coordinating Minister for Economic and Social Policies Tharman Shanmugaratnam.
He was speaking at the International Insurance Society Global Insurance Forum on Monday (Jun 13).
Mr Tharman cited growth areas in the region that insurers can tap, including providing insurance solutions for cyber and natural disaster risks, as well as investing in infrastructure.
To enable long-term investments, such as for infrastructure, Mr Tharman said the Monetary Authority of Singapore is seeking to modify its risk-based capital framework for insurers. He said the next public consultation on this will be held at the end of the month.
Mr Tharman also noted that the economic cost of natural disasters is growing but that the take-up of catastrophe insurance in Asia has been "woefully low". The Deputy Prime Minister pointed to a data gap: "The industry needs good data on the frequency, location and economic impact of natural disasters, so that insurers and reinsurers can price risks adequately. So we have had a limited supply of insurance coverage, that has itself led to higher cost of protection, which in turn discourages demand for insurance against catastrophe risks."
Likewise, Mr Tharman noted that the data needed for the efficient underwriting of cyber risk is "weak". He said: "We need to strengthen collaboration between the industry, government and academia to build reliable databases and analytical tools to enable the efficient underwriting of cyber risk."
ACTIVE INVESTMENT MANAGEMENT 'NOT ALL IT HAS BEEN CRACKED UP TO BE'
As populations age, individuals need to save more for a longer retirement. Meanwhile, slower economic growth is weighing on investment. Mr Tharman said higher savings and lower investment suggest that long-term real interest rates are likely to stay low for quite some time to come. He added that this poses a challenge for insurance and pension funds.
He said: “It hits you on both your assets and your liabilities. It means a lower return on your assets. And it pushes up the value of liabilities because the discount rate has gone down. It is not a temporary challenge but a long-term challenge.
"As life expectancy goes up, liabilities will be pushed out further, and the gap in maturity between your liabilities and your assets is likely to grow. This mismatch in durations, together with low interest rates, means we have a growing problem."
Going forward, Mr Tharman said fundamental reforms are needed to address the challenges, such as making the workplace more attractive to older employees.
As for the finance industry, he said there should be a shift towards passive investment management, away from active management which has proven costly for ordinary savers.
Mr Tharman said: “Active management is not all it has been cracked up to be: it has not proven its worth for most ordinary savers preparing for their retirement. We do have to move towards a system, in a whole range of countries, of helping people save for the long term through passive investment funds, and pool savings to avoid fragmentation and excessive marketing costs.”
- CNA/ms
- wong chee tat :)
Labels:
2016,
asia,
assets,
cash,
cashflow,
cost,
cyber security,
cyberrange,
cyberspace,
finance,
financial,
infrastructure,
insurance,
interest,
june,
market,
opportunities,
rate
Wednesday, June 8, 2016
Singapore public servants' computers to have no Internet access from May next year
Singapore public servants' computers to have no Internet access from May next year
The move is aimed at plugging potential leaks from work e-mail and shared documents amid heightened security threats.
The move is aimed at plugging potential leaks from work e-mail and shared documents amid heightened security threats. PHOTO: BLOOMBERG
PUBLISHED JUN 8, 2016, 5:00 AM SGT
Irene Tham Tech Editor
All computers used officially by public servants in Singapore will be cut off from the Internet from May next year, in an unprecedented move to tighten security.
A memo is going out to all government agencies, ministries and statutory boards here about the Internet blockade a year from now, The Straits Times has learnt.
There are some 100,000 computers in use by the public service and all of them will be affected.
"The Singapore Government regularly reviews our IT measures to make our network more secure," a spokesman for the Infocomm Development Authority (IDA) said when contacted.
The move is aimed at plugging potential leaks from work e-mail and shared documents amid heightened security threats.
Trials started with some employees within the IDA - the lead agency for this exercise - as early as April. Web surfing can be done only on the employees' personal tablets or mobile phones as these devices do not have access to government e-mail systems. Dedicated Internet terminals have been issued to those who need them for work.
The Straits Times understands that public servants will be allowed to forward work e-mails to their private accounts, if they need to.
It is rare even for banks, telcos and casinos - which are known to have the strictest computer-use policies - to cut off Internet access on all work terminals.
Banks give only some personnel - such as analysts, sales staff and corporate communications employees - Internet access, but file-sharing, Web-hosted e-mail and pornography websites are blocked. The fear is that staff may download malware accidentally from dodgy websites, or share sensitive documents online.
Mr Aloysius Cheang, Asia-Pacific executive vice-president of global computing security association Cloud Security Alliance, said the Government's move marks a return to the past - the 1990s - when Internet access was available only on dedicated terminals.
"In the past, it was hard for malware to extract sensitive information from within government networks," he said. "Now, it is hard to control any leak on social media or file-sharing sites."
It will take time to convince users about the new system as the Internet is ingrained in most work processes. One teacher noted that he uses it extensively to develop worksheets and test papers.
- wong chee tat :)
The move is aimed at plugging potential leaks from work e-mail and shared documents amid heightened security threats.
The move is aimed at plugging potential leaks from work e-mail and shared documents amid heightened security threats. PHOTO: BLOOMBERG
PUBLISHED JUN 8, 2016, 5:00 AM SGT
Irene Tham Tech Editor
All computers used officially by public servants in Singapore will be cut off from the Internet from May next year, in an unprecedented move to tighten security.
A memo is going out to all government agencies, ministries and statutory boards here about the Internet blockade a year from now, The Straits Times has learnt.
There are some 100,000 computers in use by the public service and all of them will be affected.
"The Singapore Government regularly reviews our IT measures to make our network more secure," a spokesman for the Infocomm Development Authority (IDA) said when contacted.
The move is aimed at plugging potential leaks from work e-mail and shared documents amid heightened security threats.
Trials started with some employees within the IDA - the lead agency for this exercise - as early as April. Web surfing can be done only on the employees' personal tablets or mobile phones as these devices do not have access to government e-mail systems. Dedicated Internet terminals have been issued to those who need them for work.
The Straits Times understands that public servants will be allowed to forward work e-mails to their private accounts, if they need to.
It is rare even for banks, telcos and casinos - which are known to have the strictest computer-use policies - to cut off Internet access on all work terminals.
Banks give only some personnel - such as analysts, sales staff and corporate communications employees - Internet access, but file-sharing, Web-hosted e-mail and pornography websites are blocked. The fear is that staff may download malware accidentally from dodgy websites, or share sensitive documents online.
Mr Aloysius Cheang, Asia-Pacific executive vice-president of global computing security association Cloud Security Alliance, said the Government's move marks a return to the past - the 1990s - when Internet access was available only on dedicated terminals.
"In the past, it was hard for malware to extract sensitive information from within government networks," he said. "Now, it is hard to control any leak on social media or file-sharing sites."
It will take time to convince users about the new system as the Internet is ingrained in most work processes. One teacher noted that he uses it extensively to develop worksheets and test papers.
- wong chee tat :)
Tuesday, June 7, 2016
'Alarming' rise in ransomware tracked
'Alarming' rise in ransomware tracked
By Mark Ward
Technology correspondent, BBC News
7 June 2016
Cyber-thieves are adopting ransomware in "alarming" numbers, say security researchers.
There are now more than 120 separate families of ransomware, said experts studying the malicious software.
Other researchers have seen a 3,500% increase in the criminal use of net infrastructure that helps run ransomware campaigns.
The rise is driven by the money thieves make with ransomware and the increase in kits that help them snare victims.
Ransomware is malicious software that scrambles the data on a victim's PC and then asks for payment before restoring the data to its original state. The costs of unlocking data vary, with individuals typically paying a few hundred pounds and businesses a few thousand.
Rapid growth
"Ransomware and crypto malware are rising at an alarming rate and show no signs of stopping," said Raj Samani, European technology head for Intel Security.
Ransomware samples seen by his company had risen by more than a quarter in the first three months of 2016, he added.
Mr Samani blamed the rise on the appearance of freely available source code for ransomware and the debut of online services that let amateurs cash in.
Ransomware was easy to use, low risk and offered a high reward, said Bart Parys, a security researcher who helps to maintain a list of the growing numbers of types of this kind of malware.
"The return on investment is very high," he said.
Many cyber-thieves using ransomware demand to be paid in bitcoins
Mr Parys and his colleagues have now logged 124 separate variants of ransomware. Some virulent strains, such as Locky and Cryptolocker, were controlled by individual gangs, he said, but others were being used by people buying the service from an underground market.
"It's safe to say that certain groups are behind several ransomware programs, but not all," he said. "Especially now with Eda and HiddenTear copy and paste ransomware, there are many new, and often unexperienced, cybercriminals."
A separate indicator of the growth of ransomware came from the amount of net infrastructure that gangs behind the malware had been seen using.
The numbers of web domains used to host the information and payment systems had grown 35-fold, said Infoblox in its annual report which monitors these chunks of the net's infrastructure.
"They use it and customise it for each attack, " said Rod Rasmussen, vice-president of security at Infoblox.
"They will have their own command and control infrastructure and they might use it to generate domains for a campaign," he told the BBC. "Then they'll have some kind of payment area that victims can go to."
"The different parts are tied to particular parts of the chain," he said. "Infection, exploitation and ransom."
Hidden files
The spread of ransomware was also being aided by tricks cyber-thieves used to avoid being detected by security software, said Tomer Weingarten, founder of security company SentinelOne.
"Traditional anti-virus software is not effective in dealing with these types of attacks," he said.
The gangs behind the most prevalent ransomware campaigns had got very good at hiding their malicious code, said Mr Weingarten.
"Where we see the innovation is in the infection vector," he said.
SentinelOne had seen gangs using both well-known techniques and novel technical tricks to catch out victims.
A lot of ransomware reached victims via spear-phishing campaigns or booby-trapped adverts, he said, but other gangs used specialised "crypters" and "packers" that made files look benign.
Others relied on inserting malware into working memory so it never reached the parts of a computer on which most security software keeps an eye.
"It's been pretty insane with ransomware recently," he said.
- wong chee tat :)
By Mark Ward
Technology correspondent, BBC News
7 June 2016
Cyber-thieves are adopting ransomware in "alarming" numbers, say security researchers.
There are now more than 120 separate families of ransomware, said experts studying the malicious software.
Other researchers have seen a 3,500% increase in the criminal use of net infrastructure that helps run ransomware campaigns.
The rise is driven by the money thieves make with ransomware and the increase in kits that help them snare victims.
Ransomware is malicious software that scrambles the data on a victim's PC and then asks for payment before restoring the data to its original state. The costs of unlocking data vary, with individuals typically paying a few hundred pounds and businesses a few thousand.
Rapid growth
"Ransomware and crypto malware are rising at an alarming rate and show no signs of stopping," said Raj Samani, European technology head for Intel Security.
Ransomware samples seen by his company had risen by more than a quarter in the first three months of 2016, he added.
Mr Samani blamed the rise on the appearance of freely available source code for ransomware and the debut of online services that let amateurs cash in.
Ransomware was easy to use, low risk and offered a high reward, said Bart Parys, a security researcher who helps to maintain a list of the growing numbers of types of this kind of malware.
"The return on investment is very high," he said.
Many cyber-thieves using ransomware demand to be paid in bitcoins
Mr Parys and his colleagues have now logged 124 separate variants of ransomware. Some virulent strains, such as Locky and Cryptolocker, were controlled by individual gangs, he said, but others were being used by people buying the service from an underground market.
"It's safe to say that certain groups are behind several ransomware programs, but not all," he said. "Especially now with Eda and HiddenTear copy and paste ransomware, there are many new, and often unexperienced, cybercriminals."
A separate indicator of the growth of ransomware came from the amount of net infrastructure that gangs behind the malware had been seen using.
The numbers of web domains used to host the information and payment systems had grown 35-fold, said Infoblox in its annual report which monitors these chunks of the net's infrastructure.
"They use it and customise it for each attack, " said Rod Rasmussen, vice-president of security at Infoblox.
"They will have their own command and control infrastructure and they might use it to generate domains for a campaign," he told the BBC. "Then they'll have some kind of payment area that victims can go to."
"The different parts are tied to particular parts of the chain," he said. "Infection, exploitation and ransom."
Hidden files
The spread of ransomware was also being aided by tricks cyber-thieves used to avoid being detected by security software, said Tomer Weingarten, founder of security company SentinelOne.
"Traditional anti-virus software is not effective in dealing with these types of attacks," he said.
The gangs behind the most prevalent ransomware campaigns had got very good at hiding their malicious code, said Mr Weingarten.
"Where we see the innovation is in the infection vector," he said.
SentinelOne had seen gangs using both well-known techniques and novel technical tricks to catch out victims.
A lot of ransomware reached victims via spear-phishing campaigns or booby-trapped adverts, he said, but other gangs used specialised "crypters" and "packers" that made files look benign.
Others relied on inserting malware into working memory so it never reached the parts of a computer on which most security software keeps an eye.
"It's been pretty insane with ransomware recently," he said.
- wong chee tat :)
Wednesday, April 27, 2016
Singtel launches first-of-its-kind cyber security institute in Asia Pacific
Singtel launches first-of-its-kind cyber security institute in Asia Pacific
PUBLISHED APR 26, 2016, 1:06 PM SGTUPDATED7 HOURS AGO
Sanjay Nair
SINGAPORE - Telco Singtel on Tuesday (April 26) launched its Cyber Security Institute (CSI), a hybrid between an advanced cyber range and an educational institute.
It is the first-of-its-kind in the region to test and train companies in dealing with sophisticated cyber threats.
Housed in a permanent space of over 10,000 sq ft in the eastern part of Singapore, the institute provides cyber skills development and education programmes tailored to the varying needs of company boards, C-suite management, technology and operational staff.
Boards and C-suite level participants will be trained in the areas of cyber threat awareness, risk management, business continuity planning and crisis communications. The cyber operations team will be trained in defence and response capabilities to sharpen their skills.
Singtel CEO (Group Enterprise) Bill Chang said: "Based on our engagements with companies in Singapore, more than 85 per cent do not have robust cyber response plans nor the opportunity to conduct realistic drills to test and sharpen such plans.
"This lack of cyber preparedness is worsened by the severe global shortfall of trained cyber security experts, which Forbes puts at some 1 million in 2016.
"This is why we've stepped up to the plate. We know we have to help companies secure themselves against a potential slew of increasingly sophisticated cyber attacks."
Mr Chang added that CSI aims to to arm enterprises and public agencies with the necessary know-how to counter cyber threats in a holistic manner, helping them mitigate the risks and costs associated with cyber disruptions.
The facility can emulate the environments and operations of enterprises using state-of-the-art technologies.
Like other cyber ranges, CSI can simulate cyber attacks in order to test a company's inherent vulnerabilities, defence and response capabilities.
Unlike other ranges, however, the new facility can also replicate any company's operating environment and use the latest range of cyber threats, including an extensive library of viruses and malware, to simulate attacks.
In conjunction with the launch of CSI, Singtel announced that it is the first company in Singapore to work with the Infocomm Development Authority (IDA) of Singapore on the Cyber Security Associates and Technologists (CSAT) programme.
The CSAT programme is an initiative by IDA and the Cyber Security Agency of Singapore.
As part of this programme, Singtel will train fresh infocomm technology professionals and equip them with basic cyber security skills. It will also provide experienced cyber security professionals with the opportunity to enhance their skills by training with leading cyber security experts.
Mr David Koh, chief executive of the Cyber Security Agency said: "A strong pool of cyber security talent is necessary to build a dynamic cyber security ecosystem that can support Singapore's Smart Nation journey.
"With the introduction of the CSAT programme and the setup of the Institute, we hope to encourage more to join the profession as well as enable cyber security professionals to hone their skills and stay a step ahead in the ever-evolving cyber security landscape."
- wong chee tat :)
PUBLISHED APR 26, 2016, 1:06 PM SGTUPDATED7 HOURS AGO
Sanjay Nair
SINGAPORE - Telco Singtel on Tuesday (April 26) launched its Cyber Security Institute (CSI), a hybrid between an advanced cyber range and an educational institute.
It is the first-of-its-kind in the region to test and train companies in dealing with sophisticated cyber threats.
Housed in a permanent space of over 10,000 sq ft in the eastern part of Singapore, the institute provides cyber skills development and education programmes tailored to the varying needs of company boards, C-suite management, technology and operational staff.
Boards and C-suite level participants will be trained in the areas of cyber threat awareness, risk management, business continuity planning and crisis communications. The cyber operations team will be trained in defence and response capabilities to sharpen their skills.
Singtel CEO (Group Enterprise) Bill Chang said: "Based on our engagements with companies in Singapore, more than 85 per cent do not have robust cyber response plans nor the opportunity to conduct realistic drills to test and sharpen such plans.
"This lack of cyber preparedness is worsened by the severe global shortfall of trained cyber security experts, which Forbes puts at some 1 million in 2016.
"This is why we've stepped up to the plate. We know we have to help companies secure themselves against a potential slew of increasingly sophisticated cyber attacks."
Mr Chang added that CSI aims to to arm enterprises and public agencies with the necessary know-how to counter cyber threats in a holistic manner, helping them mitigate the risks and costs associated with cyber disruptions.
The facility can emulate the environments and operations of enterprises using state-of-the-art technologies.
Like other cyber ranges, CSI can simulate cyber attacks in order to test a company's inherent vulnerabilities, defence and response capabilities.
Unlike other ranges, however, the new facility can also replicate any company's operating environment and use the latest range of cyber threats, including an extensive library of viruses and malware, to simulate attacks.
In conjunction with the launch of CSI, Singtel announced that it is the first company in Singapore to work with the Infocomm Development Authority (IDA) of Singapore on the Cyber Security Associates and Technologists (CSAT) programme.
The CSAT programme is an initiative by IDA and the Cyber Security Agency of Singapore.
As part of this programme, Singtel will train fresh infocomm technology professionals and equip them with basic cyber security skills. It will also provide experienced cyber security professionals with the opportunity to enhance their skills by training with leading cyber security experts.
Mr David Koh, chief executive of the Cyber Security Agency said: "A strong pool of cyber security talent is necessary to build a dynamic cyber security ecosystem that can support Singapore's Smart Nation journey.
"With the introduction of the CSAT programme and the setup of the Institute, we hope to encourage more to join the profession as well as enable cyber security professionals to hone their skills and stay a step ahead in the ever-evolving cyber security landscape."
- wong chee tat :)
Subscribe to:
Posts (Atom)