Sunday, February 27, 2011
Security Ward Off crime on cell phones
With Smartphones outselling PC for the first time — 421 million laptops are expected to be sold worldwide this year, according to market analysts at IDC — the wave long-predicted crime on handhelds seems to have arrived. According to mobile-security firm Lookout, malware and spyware appeared on phones 9 out of 100 which is analyzed in may, more than double the rate of 4-in-100 in December 2009.
In fact, the most practical rule to protect yourself is to start thinking of a smartphone as a PC.
Most damaging incidents on mobile devices involve bogus phone or SMS charges or Rogue mobile applications, of which there are now more than 500 varieties, according to F-Secure, a Finnish security company. All these Rus requiring users to take some kind of action such as clicking to accept or install a program, so be careful when using mobile devices can prevent most problems. (However, experts warn that automated attacks are possible and that may emerge in the future.)
Most attacks take place in Eastern Europe and China. A vast number — 88 percent, according to F-Secure — have identified devices running Nokia's Symbian operating system. Symbian is the most commonly used smartphone platform, but Nokia said this month that it would be replaced for the coming years with Microsoft Windows Phone operating system.
Early attacks, such as Cabir and Commwarrior Worm in 2004 and 2005, caused little damage. But since 2009, the attacks have grown more threatening. In September, hackers trying to steal money from accounts with a Spanish bank harmful applications on Symbian devices when they synchronized home PC infected with a malware version of ZeuS. The application enabled criminals respond to security codes sent by the Bank to validate the transfer of cash.
These attacks could be a preview of what's to come for popular devices in the United States. Criminals have attacked the phones running on Google's Android, Research In Motion's BlackBerry, Apple iPhone operating system software and Microsoft Windows Mobile, suggesting that more later.
Some experts believe that Android will become a top target for malware, because anyone can create and deploy an application anywhere on the Web. Google apps check for security issues, but has instead required technical barriers to thwart malicious activity. For example, apps run in a "sandbox", a closed environment, where they cannot influence one another or manipulate the capabilities of the device without your permission. Google removes from his official Android market any apps that break the rules against malicious activity.
Ten attacks have been directed to users of Android, including a malicious program called Geinimi that appeared in the markets of third-party Android app in China in December. This addition to legitimate applications, mostly games, allowed hackers to manipulate text messages, contact lists of stealing, make calls, visit websites and safely download files.
Attacks highlight the importance of diligence during the download of mobile applications. Users should install applications only from sites you trust. They should search apps so that they are malware. A smartphone is "a microcomputer in hand and you can get Trojans and worms and viruses, as a PC can," said Andy Hayter, anti-malcode manager at ICSA Labs, an independent safety-testing owned by Verizon.
The maniache may also want to use a security product; free and paid products are available to all, but the iPhone platform by major security companies such as F-Secure, Symantec and Kaspersky as well as specialized provider as Lookout and DroidSecurity.
Tighter controls on the use of third-party software on mobile devices can help explain the limited number of attacks so far, says Mikko Hypponen h., chief research officer at F-Secure. For example, regulated environment most of Apple has kept mostly trouble at Bay.
The malware only seen on the iPhone in 2009 occurred and affected phones that had been altered to run software that Apple doesn't allow. A worm in Australia replaced the background of the phone with an image of the singer pop 80s Rick Astley, a prank known as "rickrolling. There was also an attempt to blackmail people to pay 5 euros and a worm which tried to steal the details of the account by the customers of a Dutch Bank.
Partly for security reasons, Microsoft in October has moved towards a system for its new Windows phone 7 app that restricts the sale to its market and issued guidelines for developers that tightened security and confidentiality requirements. Microsoft says that runs tests of security in any new app.
Mr. Hypponen attacks that bill phones are the most promising way for criminals to make money, says. Hackers are understand this out, as demonstrated by the more fraud on Facebook, asking people to complete online surveys and provide mobile numbers, receiving and monthly expenses. Check your bills carefully for unusual expenses.
BlackBerry rarely are attacked because the devices are typically provided and controlled by employers, safety-conscious and mobile phones are not commonly used in countries such as Russia and China, in the homes of many creators of malware. The most common problem seen on BlackBerry — and on other platforms — are commercial spyware as FlexiSPY, which are installed secretly by somebody — usually a jealous spouse — who wants to track the position of the owner of a mobile phone, listen to the calls and read text messages and e-mail messages.
"You can even turn on your microphone remotely and hear what is being discussed around the phone, even if there is no phone calls that take place," said Mr. Hypponen.
Thursday, February 24, 2011
Smartphone: the next big security headache (PC World)
2011 is the year that mobile security is mainstream. Here at the 2011 RSA Conference in San Francisco many of security software companies I've spoken to have issued--or are planning to release an app mobile security of some kind.
And while the Smartphone is not yet an important goal in the United States, malware, there are reasons to be concerned about the future of mobile security.
One of Android is its openness. Just about anyone can write one application and deploy it without having to go through a review process long sometimes. But as is the case on the PC, this sort of openness makes it possible for malware writers to infiltrate smartphone. Security companies seem to think that Android is the next big target for malware, thanks to this opening and the fact that it runs on so many devices.
Some of the vendors I spoke also seemed concerned that the paranoia that users often make when it comes to downloading and installing the software on a PC may not carry forward to when they use a smartphone, even if there are threats.
Mobile Malware is already a problem in parts of the world. This past week, company of mobile security software that mobile Lookout found a Trojan that circulates through repackaged versions of Android apps and app deployed on alternative markets in China.
Raimund genes, Chief Technology Officer, Trend Micro, notes that malware authors are creating their own mobile shopping app to distribute malware in China. He predicts that in the United States see additional tests-concept malware mobile this year, and that it can become a serious problem in 2012.
Smartphone carrying additional information that we cannot keep on your PC, such as phone numbers of your contacts, photos, you've taken with your smartphone and so on. And unlike a PC, a smartphone that can be easily lost: you probably take your laptop with you if you get up and leave the Starbucks you're browsing the Web, but it is much easier to leave behind a smartphone.
In fact, Patrick Kennedy, Senior Director of Product Marketing with Webroot, sees this as the greatest threat to Smartphone now. And not surprising, many security smartphone applications that we have seen so far put great emphasis on the protection of your personal information if your smartphone gets lost or stolen.
Smartphone malware is in its infancy and is difficult to say what will happen next, but all signs point toward some serious problems in the not too distant future. In the meantime, keep the guard, remain vigilant and think before you install the next app.
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
Microsoft has fixed a Security Bug in its antivirus-
Microsoft has corrected a bug in its malware scanning engine that could be used as a stepping stone to an attacker trying to hijack a Windows window.
The bug is fixed in an update to the Microsoft Malware Protection Engine that has been pushed out to users of security products from Microsoft on Wednesday. Is what is known as an elevation of privilege vulnerability--something that could be used by an attacker who already has access to the Windows system to capture the full administrative control.
Microsoft has not seen anyone exploit the bugs still--the defect was reported to the company by Cesar Cerrudo security researcher--but Microsoft thinks that hackers could develop code that exploits the issue reliably.
In an interview of instant message, Cerrudo, CEO of security research firm Argeniss, said that he disclosed publicly Conference Black Hat security bug in July 2010. But because the hacker need would already have access to the machine to pull off this attack, he does not believe that presents a serious security risk for most users.
"This vulnerability can be exploited remotely, for instance on the Internet Information Server, but the attacker must be able to upload any code running on IIS," he said. "Sites that allow users to upload Web pages, are most at risk."
Microsoft rates it as "important".
An attacker could exploit this flaw by changing a Windows registry key to a special value, who would then processed by the engine at its subsequent malware scan.
This would be useful if the criminal was already on a machine that had the blocked user's privileges. "An attacker who successfully exploited this vulnerability could run arbitrary code ... and take complete control of the system," Microsoft said in a security advisory released Wednesday. "An attacker could then install programs; view, edit, or delete data; or create new accounts with full user rights.
The issue is fixed in version 1.1.6603.0 of the Malware Protection Engine, which is used in Windows Live OneCare, Microsoft Security Essentials, Windows Defender, Forefront Client Security, Forefront Endpoint Protection 2010 and the Microsoft Malicious Software Removal Tool.
Consumers should obtain the fix automatically as part of the monthly update of Microsoft to its malware scanner.
This is not the first time that Microsoft has found bug in its security software. Bug in Malware Protection Engine is reportedly back in 2007 and 2008.
Robert McMillan covers the security of your computer and General technology breaking news for the IDG News Service. Follow Robert on Twitter at @ bobmcmillan. E-mail address is robert_mcmillan@idg.com, Robert
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
Friday, February 18, 2011
Tablets and Smartphones force Cisco to rethink security
SAN FRANCISCO--Cisco has unveiled a security architecture "complicated" self-describing on FutureX & equip dubbed says provides a context-aware to safeguard networks increasingly overrun with Smartphones, tablets, and virtualization.
On FutureX & equip, outlined the RSA Conference in San Francisco, initially give Cisco firewalls--and, finally, his switches, routers and other products--the ability to dynamically scan and label data concerning the identity of a user and using application/device in order to have a real time basis for the application of a security policy based on identity.
Tom Gillis, vice president and general manager of Cisco security technology business unit, recognized on FutureX & equip architecture is complex and novel, and its evolution in terms of product implementation only slowly starts to roll out this year.
ANALYSIS: is a next-generation firewall in your future? | HP accuses Cisco data center standard deflect
The ability to be evident on FutureX & equip should first in the line of multi-use Cisco Adaptive firewall Security Appliance (ASA), which will be equipped with Cisco TrustSec tagging technology to identify a wide range of information about using the network to a user, such as applications, devices, location and time of day, so that security decisions can be made in a context-aware fashion.
"What context will reveal? That someone is, they are part of an organization, what applications are trying to use, they use an iPhone and iPad and is managed by it, "and are inside or outside the corporate network, says Ambika Gadre, senior director of Cisco security technology business unit.
The idea is to flag policy violations, block access or warn of security threats. On FutureX & equip is seen as increasing borderless Cisco networks strategy cycles, which is intended to support applications, processes and services that are increasingly distributed and virtualized, such as those in it environments and software-as-a-service cloud.
"Owns," Gillis recognized when asked if the architecture on FutureX & equip never stretches to embed gear safety or third-party network. But Cisco executives said they are weighing how to create a shared global ecosphere for it, probably by making available APIS or approaching a standards body with some related fundamental technology on FutureX & equip.
Cisco is a great player in the network security market, with approximately 2 billion dollars in sales last year. But the consumerization of endpoint devices such as Apple's iPad and iPhone, as well as mobile devices running Google Android and other software is required in your organization, "is causing us to rethink how security," says Gillis. The spread of virtualized systems is also a big part of that mix, he says.
Cisco provides on FutureX & equip as a way to not only give our customers a broad view of what they are doing on your network computers and users of mobile devices, but to enforce granular policies, such as access to applications on Facebook. There is also the idea that the fusion of some tag identity and device information data with the data accumulated by Security threat Intelligence operations, Cisco, a cloud-based service to analyze information about ongoing threats globally, would advance enabled the security context. Cisco will also accumulate telemetry data culled from actions of situational AnyConnect VPN client and legacy, that its customers use to apply this context-aware security more than 150 million.
Deciphering On Futurex & Equip
In trying to absorb what the heck is talking with Cisco on FutureX & equip--especially with no demonstrable product for show--analysts were somewhat divided.
Gartner analyst Neil MacDonald called on FutureX & equip and the transition to the knowledge based on context "very interesting" and applauded "the wealth of ideas".
But other analysts were skeptical about it, above all its complexity and intimidation Cisco was going on a tangent that was unlikely to benefit the rest of the security industry.
"I wish that Cisco would stop misrepresentation in the areas of security, taking the jumble of some products and mix them into a General over-branded architecture," said Richard Stiennon, analyst at IT-harvest. "Have nothing to show us," he said, adding that if the concept has some chance, the company shall give proof of something important in the next 12 months.
In the next 12 months, Cisco promises to get on FutureX & equip in his line of appliances of ASA. But when asked if this will be a software upgrade or require new hardware, Cisco executives say that they are not safe. "This is to be determined," said Fred Kost, marketing director of security solutions.
Read more about wide area network in Wide Area Network network in the world.
For more information on the corporate network, go to NetworkWorld. Story copyright 2010 Network World Inc. All rights reserved.Virtualization is a key factor in Cloud security
SAN FRANCISCO--virtualization technologies allow you to better control and security in cloud computing environments, said Art Coviello, RSA Chief today.
In a keynote address at the RSA Security Conference here, Coviello has hit an optimistic tone about cloud security issues. While he recognized some of the concerns enterprises might have about how to move data and applications to the cloud, said that approaches to address possible issues are closer than many think.
"Trust in the cloud is feasible today," Ivanov said, adding that the key is to stop depending on the security controls designed for physical infrastructure. Instead, companies should consider leveraging virtualization technologies to enable advanced security, visibility and control they want in cloud environments.
Coviello argued that security needs to be approached to information or transactions which is protecting. In virtual environments, static damage perimeter way logical boundaries defined by information and transactions. Therefore safety must become logical as well.
"The stack IT is changing. Our borders are logical, rather than physical. We can not depend on the physical infrastructure for security, "he said.
Virtual machines are designed by nature to adjust dynamically loads of work, he said. As a security really work in these types of environments, the controls must be just as dynamic. "That means building security in virtualized components and, by extension, distribution of safety throughout the cloud," he said.
Security policies and best practices must be encoded and enforced by systems of automated security management for the cloud, Coviello said. The focus should be on enabling protection that is more risk-based and adaptable to changing conditions--and less static.
The economy and agility enabled by cloud computing are pushing more and more companies to adopt it, regardless of security and control concerns they may have, he said.
Counterintuitive as it may seem, "if properly exploited, virtualisation can be a path toward overcoming the level of control and visibility that exists today in physical environments," he said.
As part of its effort to enable RSA Security, the company launched a service called RSA cloud Trust Authority, Coviello said. The service will leverage VMware virtualization tools to provide a set of compliance monitoring in cloud services and identity management.
Jaikumar Vijayan covers data security and privacy issues, security, financial services and e-voting for Computerworld. Follow Jaikumar on Twitter at @ jaivijayan or Subscribe to the RSS feed of Jaikumar. His e-mail address is jvijayan@computerworld.com.
To learn more about security in Computerworld Security Center topic.
For more enterprise computing news, visit Computerworld. Story copyright © 2010 Computerworld Inc. All rights reserved.
Tuesday, February 15, 2011
Oracle plugs 21 dangerous security holes in Sun Java
Daniel Kennedy leads initiatives in politics and in the management of operational safety, conducts the certification strategy and risk assessment and is head of business continuity planning and disaster recovery to the Praetorian security group, LLC.
Praetorian Security Group first, Daniel was the global head of information security at D.B. Zwirn & co where he managed the company's information security. He was specifically responsible for the development, implementation and maintenance of information security policy of the company. Managed security metrics reporting, also the program of awareness raising and education of safety, security incident response, security control and develop the company's strategy for the security technology. In this role he worked closely with the firm's CIO, COO, head of compliance, head of legal, head of infrastructure, head of client services overseas and IT managers.
Before D.B. Zwirn, Daniel was Vice President and program director for the security application program at Pershing LLC, a division of the Bank of New York. Responsibilities of Daniel including management of the firm's application security, coordination of application vulnerability assessments and testing, application security, training, documentation of the secure coding guidelines and application security development firm SDLC penetration. He was the primary liaison for application security concerns among teams as the Information Security Office, Internal Audit, risk of Information Management (IRM) and teams of business and application development. He served on several committees, including the security infrastructure, Workgroup and chartered security architecture and chaired the Security Council of the enterprise application, an interdisciplinary team consisting of application developers and security experts on the subject.
His previous positions include the Pershing and development management positions in systems engineering of web applications creation company to facilitate the online brokerage. He was also employed at Donaldson, Lufkin & Jenrette Inc., a technology analyst for the Treasury.
Daniel Degree Master of Science in information systems from Stevens Institute of Technology, a Master of Science in information assurance from Norwich University and a Bachelor of Science in Information Management and Technology from Syracuse University. He is certified as a CEH (Certified Ethical Hacker) of the EC-Council, a CISSP and an NASD Series 7 license.
You can also follow him on Twitter, and the Praetorian Prefect of blog.