Tuesday, November 11, 2008

Rampant Malware Drive-by-downloads

Hi Folks,

Drive-by-downloads are rampant. They infect your machine with malware when you simply visit a website. No clicking on links or user interaction is required; you simply get infected when your browser loads the page. Following is a link to an article about such a sample attack from last month:

http://www.theregister.co.uk/2008/11/10/drive_by_download_mass_attack/

And, the cybercrime economy is growing due to the economic downturn:

http://arstechnica.com/news.ars/post/20081023-malware-writers-ratchet-up-attacks-as-stock-market-tanks.html

http://www.informationweek.com/news/security/cybercrime/showArticle.jhtml;jsessionid=Y132JJQO0YUMIQSNDLRSKH0CJUNN2JVN?articleID=212101494&cid=tab_art_int

Google is doing some great work in this area by flagging web sites that get infected so that you are protected while you are searching by displaying a message saying "This site may harm your computer" below infected links in their search results:











Google also provides the list of infected sites to Firefox and Chrome browsers, so that users can be protected not only while they are searching but can be protected wherever they happen to be browsing on the Internet.

Yahoo provides similar protections through a feature called SafeSearch that they have deployed in partnership with McAfee. Finally, Microsoft is also slated to provide anti-malware protection as part of the next version of Internet Explorer.

There is much good work that search engines and browsers are doing to help protect users! Detection systems are working to avoid false positives (when a web site gets blacklisted even though they are not really infected), potentially at the expense of false negatives (in which a web site does not get blacklisted even though it is infected). I hope that over time Google, Yahoo, and Microsoft crack down even more aggressively on this problem so that unsuspecting users don't get infected, and the growth of botnets resulting from such malware infections can be curtailed.

Thoughts? Comments? Questions?

Let's keep fighting the fight!

Sincerely,

-- Neil
http://www.neildaswani.com

Learn more about security from Stanford's Advanced Computer Security Certificate Program-- click on http://tinyurl.com/2286xw for more information.

My book, "Foundations of Security: What Every Programmer Needs To Know" is available at http://tinyurl.com/33xs6g

Sunday, April 13, 2008

Crimeware: It's out!

Over the past few years, one of the biggest shifts impacting security online has been that the attacks are no longer primarily conducted by teenagers writing viruses and worms to make a name for themselves, but instead are executed by financially motivated cybercriminals.

A book entitled Crimeware: Understanding New Attacks and Defenses by Markus Jakobsson and Zulfikar Ramzan (to be officially released this week) is the most comprehensive compilation to-date that I am aware of cataloguing the many different ways that cybercriminals manipulate web sites, software, and people to make money online. While the book is to be officially released on April 19, I was able to pick up a copy at the on-site bookstore at the RSA conference last week!

A chapter co-authored by yours truly and a distinguished team of Googlers on "Online Advertising Fraud" appears in the book, along with chapters on topics such as "Crimeware in the Browser" (Dan Boneh, et al.), "A Taxonomy of Coding Errors" (Gary McGraw), and "Technical Defense Techniques" (Peter Ferrie, et. al)





The chapters in the book provide deep dives into topics that not only describe the vulnerabilities that cyberattacks prey on, but also provide a guide to high-level defenses. As such, the book is a great read for CIOs and CSOs in addition to security researchers-- I highly encourage checking it out!

Sunday, January 20, 2008

CIA: Hackers Shook Up Power Grids


For those of you that saw the movie "Matrix Reloaded," you may (or may not) remember a 3-second scene in which Trinity, played by Carrie-Anne Moss, takes advantage of a buffer overflow exploit as part of an attack to shut down a power grid. (Matrix Reloaded was one of the first movies, I believe, to get some of the technical details right on the big screen-- see "Matrix Sequel Has Hacker Cred" at the Register for more details-- whereas most other movies show silly animations for cyberattacks.)

Well, it seems that the CIA tells us that attacking power grids via the Internet is possible, and has been attempted (albeit outside the U.S.). I'm not sure if the technical details have been disclosed (yet?), but there's some rumblings that the attacks required some insider information, which is not surprising but no less comforting, and that extortion has been the attackers' goal to date. Here's an article:

CIA: Hackers Shook Up Power Grids
http://blog.wired.com/defense/2008/01/hackers-take-do.html

(Similar articles are available at http://news.google.com/news?hl=en&ned=us&ie=UTF-8&ncl=1126553310 )

Saturday, January 12, 2008

Report: TSA Site Exposed Travelers To ID Theft

Report: TSA Site Exposed Travelers To ID Theft

Check out the following report on a TSA sponsored web site that exposed citizen's PII (personally identifiable information) including social security numbers to identity theft:

http://tinyurl.com/yp5j3e

-- Neil

Monday, December 3, 2007

Security tidbits from the past month...

Web applications and Microsoft Office are the current major pain-points:

http://www.washingtonpost.com/wp-dyn/content/article/2007/11/29/AR2007112900062.html?wpisrc=newsletter

"Developers aren't using secure coding techniques to create Web applications, giving hackers an opportunity to tap the rich databases of information connected to them, according to SANS, a computer training and security organization."


The TJX hack just keeps getting worse:

Update: TJX Victim Tally Rises to 94M
http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=306333&intsrc=news_ts_head
"In an affidavit, the bankers said that "TJX continues to downplay the seriousness of the situation."

Details emerge on TJX breach
http://www.boston.com/business/globe/articles/2007/10/25/details_emerge_on_tjx_breach/
"Spokespeople for Visa and MasterCard said they wouldn't comment on the matter, or on a Visa official's estimate of losses to banks that issued cards to be between $68 million to $83 million."

"Visa fined TJX's card processor $880,000 last summer, and said it would continue to fine the retailer's card processor $100,000/month, for TJX's role in the worst data breach in the payment industry's history, according to documents filed in federal court Oct. 26."

VISA Fined TJX Processor for Security Breach
http://www.eweek.com/article2/0,1895,2208927,00.asp
TJX IT staff knew about the vulnerabilities, but continued to ignore them because they wanted to save money...

TJX violated nine of 12 PCI controls at time of breach, court filings say
http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9044321&intsrc=hm_list
"these additional facts materially support the claim that TJX's
conduct generally" violated laws governing unfair trade practices,
they said.

Court filing: TJX was warned about lax security before massive breach
http://www.mercurynews.com/business/ci_7290184

Thursday, October 18, 2007

It's completely online!

Dear Readers in the Blog-o-sphere,

Over the past few years, I have been helping Stanford build a hands-on advanced secuirty certification program to arm new and existing software engineers with what they need to know to mitigate cyberattacks. Today, Stanford announced that they have made the entire program available online, whereas students typically had to come to campus to complete the program.

The certification program provides hands-on training to geographically distributed engineering and IT staff to help them defend their companies against the changing landscape of Internet threats. More information and the press release are available at:

http://tinyurl.com/25eujb

Specific topics covered in the certification program include:
  • emerging threats such as botnets and phishing and defenses against them,
  • the most recent growing web vulnerabilities, such as cross-site
    scripting, SQL injection attacks, and distributed denial-of-service
    (DDoS), and
  • traditional topics such as buffer overflows, dictionary attacks,
    authentication, access control, data integrity, symmetric encryption,
    public-key cryptography, and much, much more.
Please feel free to contact Eve Byer (ebyer@stanford.edu) for more information about the program!

Sincerely,

-- Neil
http://www.neildaswani.com

My new book, "Foundations of Security: What Every Programmer Needs To Know" is available at http://tinyurl.com/33xs6g

Learn more about security from Stanford's Advanced Computer Security Certificate Program-- click on http://tinyurl.com/2286xw for more information.

Sunday, August 19, 2007

What does Neil work on at Google?

Hi Folks,

Some of you have complained that I don't tell you about what I work on at Google... well, I certainly can't tell you about everything that I work on, but here is some info about a "launch" that I contributed to...

Google launched the "ad traffic quality" center late last week featuring articles by yours truly:

http://www.google.com/adwords/adtrafficquality/tech.html

More articles about the launch are at:

http://news.google.com/news?hl=en&ned=us&q=%22ad+traffic+quality%22&btnG=Search+News

So, please... no more complaints! You now know something about what I work on!

Sincerely,

-- Neil
http://www.neildaswani.com

My new book, "Foundations of Security: What Every Programmer Needs To Know" is available at http://tinyurl.com/33xs6g

Learn more about security from Stanford's Advanced Computer Security Certificate Program-- click on http://tinyurl.com/2286xw for more information.