Sunday, November 30, 2008
Obama Trojan
Ever since the end of the election, there has been a Trojan virus that has been riding the coattails of the Obama victory speech. here is a quote from the article " Several security tool vendors -- including Cloudmark, Sophos, and Websense -- today are reporting massive amounts of spam messages that promise video clips of an "amazing" Obama speech, election news results, or interviews with Obama's advisers. These messages are carriers of malware that can compromise users' PC, researchers say. The three vendors offered differing descriptions of the attack, which suggests it may be working under different disguises. But screen shots provided by both Cloudmark and Sophos contained identical photos and text, indicating that much of the traffic is being generated by a single exploit."
here is the website with more news
http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=212000783&cid=nl_DR_WEEKLY_H
With every big event there are huge malware attacks reported. So my question is why aren't there more arrest made or more of an attempt to catch these people and have them made an example of. And on the other side of things, what are some techniques that are being used to hide the identity of the hackers sending out these viruses. How have these people hide their foot prints
here is the website with more news
http://www.darkreading.com/security/attacks/showArticle.jhtml?articleID=212000783&cid=nl_DR_WEEKLY_H
With every big event there are huge malware attacks reported. So my question is why aren't there more arrest made or more of an attempt to catch these people and have them made an example of. And on the other side of things, what are some techniques that are being used to hide the identity of the hackers sending out these viruses. How have these people hide their foot prints
Virus attack on London hospitals hits patient care
During the week of November 19 three London hospitals were down because of infection of malware.
Question:
If there are Malware infection with no threat what are some other reasons for malware to be put in place if there not negative effects?
No patient data was at risk of disclosure, said William Mach, an NHS spokesman. As a precaution, computers were shut down at St Bartholomew's, the Royal London Hospital and The London Chest Hospital.
When the infection became known, ambulances were diverted to other hospitals, as it was easier to admit patients using unaffected computer systems rather than revert to a paper-based admission systems, Mach said.
The hospitals are now taking emergency patients again, he said.
Official are investigating how the infection occurred, although it did not appear to be malicious, Mach said.
Here is a site with more information:
Question:
If there are Malware infection with no threat what are some other reasons for malware to be put in place if there not negative effects?
Monday, November 24, 2008
ND Stadium Security - A Unique Case Study
One thing nearly all of us take part in during the Fall on campus is Notre Dame football. The student security at the stadium is rather simple - you hand them your ticket and show a student ID. The ID card is the chief security check that you, as a student, are entitled to be there. Your clearance is a photo and a name to match the name on the ticket. It's easy to see that a ticket booklet name could be forged and a fake ID made to match it, but is all that really necessary to get past stadium security?
A friend of mine and I wore chicken and gorilla suits to the game this weekend against Syracuse. Maybe you saw us... As you can see below, we were fully masked. You may be surprised to learn that we wore the masks all the way from his room in Morrissey up to around the end of the first quarter. We were able to walk past a number of ushers, many of whom acknowledged us, without removing the masks on our way into the stadium and our seating section. We could have been anybody. Our photo IDs certainly did not match our gameday appearance. I'm not particularly serious or worried about threats from criminals in animal costumes, but I do think it's something to think about and, if nothing else, pretty funny.
A friend of mine and I wore chicken and gorilla suits to the game this weekend against Syracuse. Maybe you saw us... As you can see below, we were fully masked. You may be surprised to learn that we wore the masks all the way from his room in Morrissey up to around the end of the first quarter. We were able to walk past a number of ushers, many of whom acknowledged us, without removing the masks on our way into the stadium and our seating section. We could have been anybody. Our photo IDs certainly did not match our gameday appearance. I'm not particularly serious or worried about threats from criminals in animal costumes, but I do think it's something to think about and, if nothing else, pretty funny.
Final Exam
The final exam for this course will be on Tuesday, December 16th from 8AM-10AM. This time and the location are set by the Registrar's Office. If you have a conflict, you need to see me as soon as possible.
The Registrar's Office has not yet announced our room assignment. Please pay careful attention to this announcement when it is made. I have had semesters where the final exam room was different from my normal classroom.
I've posted a review sheet that outlines the material covered by the exam. We will also use the last class meeting to review any questions that you may have, so please take some time to prepare in advance.
The Registrar's Office has not yet announced our room assignment. Please pay careful attention to this announcement when it is made. I have had semesters where the final exam room was different from my normal classroom.
I've posted a review sheet that outlines the material covered by the exam. We will also use the last class meeting to review any questions that you may have, so please take some time to prepare in advance.
Sunday, November 23, 2008
Pentagon Hit By Cyberattack
The original articles for the subsequent post can be found here and here.
According to two news articles from Foxnews.com, the Department of Defense--specifcally, the Pentagon--has been the target of a serious cyberattack. The cyberattack has, reportedly, affected some of the 17 million computers that store sensitive information on the Global Information Grid. According to the articles, the cyberattack came in "the form of a global virus or worm that is spreading rapidly through a number of military networks." As a result of this attack by commercial malware, use of external hardware devices such as flash drives, external hard drives, and DVD's has been banned.
As to the cause of this cyberattack, not many specifics are known. A rear admiral in the United States Navy has reportedly attributed the introduction of the global worm "to a service member with access to classified information [that] inadvertently loaded the virus onto his computer via a flash drive." This also explains why external devices such as flash drives have been banned. The authors of the malware--and the architects of the cyberattack--are as yet unknown. In fact, the cyberattack could have come "from a number of foreign countries, possibly Russia, though the military is dismissing earlier reports that China was the source of the threat."
Now that the Department of Defense has detected the virus, the next thing they need to do is follow the incident handling process described in class. Namely, they should contain the virus by removing the ways in which the virus is thought to have entered the network. I believe that the Department of Defense has done that very thing by prohibiting the use of external drives. They then must restore their systems to a "known good state," but the details of that may be difficult since we do not know the extent to which the network has been damaged by this cyberattack. In restoring their systems to a "known good state," they may have to rebuild their systems entirely or they may just have to redesign their information security environment. Finally, they must analyze how to prevent further such cyberattacks. That may require further restricting access to sensitive information, or permanently enforcing the ban on all external devices.
According to two news articles from Foxnews.com, the Department of Defense--specifcally, the Pentagon--has been the target of a serious cyberattack. The cyberattack has, reportedly, affected some of the 17 million computers that store sensitive information on the Global Information Grid. According to the articles, the cyberattack came in "the form of a global virus or worm that is spreading rapidly through a number of military networks." As a result of this attack by commercial malware, use of external hardware devices such as flash drives, external hard drives, and DVD's has been banned.
As to the cause of this cyberattack, not many specifics are known. A rear admiral in the United States Navy has reportedly attributed the introduction of the global worm "to a service member with access to classified information [that] inadvertently loaded the virus onto his computer via a flash drive." This also explains why external devices such as flash drives have been banned. The authors of the malware--and the architects of the cyberattack--are as yet unknown. In fact, the cyberattack could have come "from a number of foreign countries, possibly Russia, though the military is dismissing earlier reports that China was the source of the threat."
Now that the Department of Defense has detected the virus, the next thing they need to do is follow the incident handling process described in class. Namely, they should contain the virus by removing the ways in which the virus is thought to have entered the network. I believe that the Department of Defense has done that very thing by prohibiting the use of external drives. They then must restore their systems to a "known good state," but the details of that may be difficult since we do not know the extent to which the network has been damaged by this cyberattack. In restoring their systems to a "known good state," they may have to rebuild their systems entirely or they may just have to redesign their information security environment. Finally, they must analyze how to prevent further such cyberattacks. That may require further restricting access to sensitive information, or permanently enforcing the ban on all external devices.
Thursday, November 20, 2008
Assignment 6
Assignment 6 is now available. It is due on December 8th. The first part of the assignment involves tracking down IP addresses. The second part of the assignment is the analysis of the iPremier case, which I will distribute in class on Monday.
Subscribe to:
Posts (Atom)