This content is restricted.
Author: admini
Cyber crime ‘costs small companies £800m a year’
The lobby group is concerned that the cost to the wider economy could be much greater, as small businesses refuse to trade online because they believe the security framework does not give them adequate protection.
Mike Cherry, FSB chairman, said: “Cyber crime poses a growing threat for small firms and it isn’t something that should be ignored. “While we want to see clear action from the Government and the wider public sector, there are clear actions that businesses can take to help themselves.”
The FSB issued 10 tips to help businesses protect themselves, including a combination of standard security protection steps (e.g. putting up a firewall and using antivirus and anti-spam software); carrying out regular security updates on all software and devices; and ensuring there is a resilient IT system and email password policy. The Government has urged small companies to spend more on security to address the rise in cyber crime and meet the terms of a tough EU directive.
New Security Intelligence Solution, EnCase® Analytics, Unveiled by Guidance Software
“One of the main goals of big data security analytics is to improve operations and accelerate incident detection/response,” said Jon Oltsik, senior principal analyst at the Enterprise Strategy Group. There is a need for solutions to easily discover changes in the system, trends and patterns, and other anomalous behavior that may expose signs of risks and threats.”
With EnCase Analytics, we are leveraging this expertise to empower organizations to derive useful insights from the noise that endpoint data produces,” said Victor Limongelli, chief executive officer, Guidance Software, Inc. “Unlike other endpoint security solutions, EnCase Analytics does not rely on signatures, heuristics or indicators, but instead leverages big data analytics to draw useful connections between seemingly unrelated activities in disparate data types.” EnCase Analytics leverages data from across all your endpoints from the kernel level instead of trusting a compromised operating system, resulting in a repository of the most reliable and useful data for insights into undetected risks and threats.
Link: http://www.it-analysis.com/technology/security/news_release.php?rel=38406
In a sea of malware, viruses make a small comeback
“Although we don’t have complete data for all the aforementioned locations, we can see that 30 percent to 40 percent of computers in some of these locations do not have up-to-date real-time anti-virus software installed, compared to the worldwide average of 24 percent,” Rains wrote.
More than 8 million computers worldwide are infected with Sality, a virus that infects files with certain extensions such as “.scr” and “.exe” and can also shut down the processes and services of security software, he wrote.
To infect computers, Sality has used a vulnerability that was also targeted by Stuxnet, the malware designed to wreck Siemens equipment used by Iran in its nuclear fuel refinement program.
DHS Eyes Sharing Zero-Day Intelligence With Businesses
The DHS pitch: We’ll share intelligence gleaned from the U.S. government’s vast stockpile of zero-day vulnerabilities — purchased from bug hunters and resellers — to help block zero-day threats. “It is a way to share information about known vulnerabilities that may not be commonly available,” Homeland Security secretary Janet Napolitano said Wednesday at the Reuters Cybersecurity Summit in Washington, D.C., reported Reuters. The DHS proposal is a continuation of the February 2013 executive order and related presidential policy directive issued by President Obama, which created a public-private cyber-threat information sharing regime, as well as voluntary private sector cybersecurity standards.
The executive order expanded the Enhanced Cybersecurity Services program — formerly known as the Defense Industrial Base pilot — to share threat information, including classified intelligence, with defense contractors, telecommunications and other critical-infrastructure firms that have appropriate security clearances.
But the suggestion has drawn the ire of privacy and civil rights groups, which object to giving blanket immunity to any business that shares customer and employee information — potentially including full texts of all emails sent and received via business networks — with intelligence agencies.
Outsourcing zero-day-vulnerability scanning to a private business, however, would seem to obviate related privacy concerns, since network providers already scan their customers’ network traffic for some signs of attack.
The offer of shared threat intelligence is a crucial incentive for getting private businesses to agree to participate in the government’s cybersecurity program, which is designed in large measure to better secure the critical infrastructure, which is largely owned by private businesses.
To date, the large sums of money on offer for buying zero-day vulnerabilities have seen the bug-buying restricted to organizations, criminal gangs or governments with deep enough pockets, and presumably a need to put the vulnerabilities to use.
Furthermore, some information security experts have warned that the move to share threat intelligence gathered by the NSA and other agencies could further bolster the bug vulnerability marketplace and potentially direct tax dollars to anti-U.S. hackers who are expert bug hunters, as opposed to spending that money on defense.
“If the U.S. government knows of a vulnerability that can be exploited, under normal circumstances, its first obligation is to tell U.S. users,” former White House cybersecurity advisor Richard Clarke told Reuters.
“NSA, CIA and military are now #1 buyers of exploits, while DHS, which is responsible for cyber defense, has lost most of its top officials,” said Christopher Soghoian, principal technologist and senior policy analyst for the ACLU’s Speech, Privacy and Technology Project, via Twitter.
New Mac spyware found in the Oslo Freedom Forum
This content is restricted.