The United States faces "serious and significant" threats within cyberspace, the White House's top counter-terrorism advisor said Sunday, adding it was an issue of national security.
"The threats and the vulnerabilities within the cyber domain are serious and significant," John Brennan told NBC, adding a cybersecurity board had been set up at the White House.
"It's a very complex and complicated challenge, but we are working very closely with the private sector."
Last month a row over Internet freedom erupted between China and the United States as Beijing denied any state involvement in cyberattacks on Internet search engine Google.
President Barack Obama said he was "troubled" by Google's statements it had been attacked by China-based hackers, and demanded official answers.
The US Internet giant has threatened to abandon its Chinese search engine, and perhaps end all operations in the country over the cyberattacks. It has also said it is no longer willing to bow to Chinese government censors.
"We're looking at these issues from the standpoint of espionage, from governments, from different individuals, whether they be hackers or terrorist organizations," Brennan said. afp
Monday, February 8, 2010
Wednesday, February 3, 2010
Senators Warned of Terror Attack on U.S. by July
America’s top intelligence official told lawmakers on Tuesday that Al Qaeda and its affiliates had made it a high priority to attempt a large-scale attack on American soil within the next six months.
The latest on President Obama, his administration and other news from Washington and around the nation. Join the discussion.
The assessment by Dennis C. Blair, the director of national intelligence, was much starker than his view last year, when he emphasized the considerable progress in the campaign to debilitate Al Qaeda and said that the global economic meltdown, rather than the prospect of a major terrorist attack, was the “primary near-term security concern of the United States.”
At Tuesday’s hearing, Senator Dianne Feinstein, Democrat of California and chairwoman of the Senate Intelligence Committee, asked Mr. Blair to assess the possibility of an attempted attack in the United States in the next three to six months.
He replied, “The priority is certain, I would say” — a response that was reaffirmed by the top officials of the C.I.A. and the F.B.I.
Citing a recent wave of terrorist plots, including the failed Dec. 25 attempt to blow up an airliner as it approached Detroit, Mr. Blair and other intelligence officials told a Senate panel that Al Qaeda had adjusted its tactics to more effectively strike American targets domestically and abroad.
“The biggest threat is not so much that we face an attack like 9/11,” said Leon E. Panetta, the C.I.A. director. “It is that Al Qaeda is adapting its methods in ways that oftentimes make it difficult to detect.”
As the C.I.A. continues its drone attacks aimed at Qaeda operatives in Pakistan, the officials also said that the network’s splinter groups in Yemen and Somalia were taking on more importance.
But Mr. Blair began his annual threat testimony before Congress by saying that the threat of a crippling attack on telecommunications and other computer networks was growing, as an increasingly sophisticated group of enemies had “severely threatened” the sometimes fragile systems undergirding the country’s information infrastructure.
“Malicious cyberactivity is occurring on an unprecedented scale with extraordinary sophistication,” he told the committee.
His emphasis on the threat points up the growing concerns among American intelligence officials about the potentially devastating results of a coordinated attack on the nation’s technology apparatus, sometimes called a “cyber-Pearl Harbor.”
He said that the surge in cyberattacks, including the penetration of Google’s servers from inside China, was a “wake-up call” for those who dismissed the threat of computer warfare. “Sensitive information is stolen daily from both government and private-sector networks, undermining confidence in our information systems, and in the very information these systems were intended to convey,” Mr. Blair said.
The latest on President Obama, his administration and other news from Washington and around the nation. Join the discussion.
The assessment by Dennis C. Blair, the director of national intelligence, was much starker than his view last year, when he emphasized the considerable progress in the campaign to debilitate Al Qaeda and said that the global economic meltdown, rather than the prospect of a major terrorist attack, was the “primary near-term security concern of the United States.”
At Tuesday’s hearing, Senator Dianne Feinstein, Democrat of California and chairwoman of the Senate Intelligence Committee, asked Mr. Blair to assess the possibility of an attempted attack in the United States in the next three to six months.
He replied, “The priority is certain, I would say” — a response that was reaffirmed by the top officials of the C.I.A. and the F.B.I.
Citing a recent wave of terrorist plots, including the failed Dec. 25 attempt to blow up an airliner as it approached Detroit, Mr. Blair and other intelligence officials told a Senate panel that Al Qaeda had adjusted its tactics to more effectively strike American targets domestically and abroad.
“The biggest threat is not so much that we face an attack like 9/11,” said Leon E. Panetta, the C.I.A. director. “It is that Al Qaeda is adapting its methods in ways that oftentimes make it difficult to detect.”
As the C.I.A. continues its drone attacks aimed at Qaeda operatives in Pakistan, the officials also said that the network’s splinter groups in Yemen and Somalia were taking on more importance.
But Mr. Blair began his annual threat testimony before Congress by saying that the threat of a crippling attack on telecommunications and other computer networks was growing, as an increasingly sophisticated group of enemies had “severely threatened” the sometimes fragile systems undergirding the country’s information infrastructure.
“Malicious cyberactivity is occurring on an unprecedented scale with extraordinary sophistication,” he told the committee.
His emphasis on the threat points up the growing concerns among American intelligence officials about the potentially devastating results of a coordinated attack on the nation’s technology apparatus, sometimes called a “cyber-Pearl Harbor.”
He said that the surge in cyberattacks, including the penetration of Google’s servers from inside China, was a “wake-up call” for those who dismissed the threat of computer warfare. “Sensitive information is stolen daily from both government and private-sector networks, undermining confidence in our information systems, and in the very information these systems were intended to convey,” Mr. Blair said.
Tuesday, February 2, 2010
Cyberthieves are hiring, using online ads
The people who brought the world malicious software that steals credit card numbers from your personal computer and empties bank ATMs of their cash are hiring, and they're advertising online.
Two companies that are hiring -- at least on a contractor basis -- advertise online, said Kevin Stevens, a threat intelligence analyst for SecureWorks, who presented findings on the organizations at the Black Hat cybersecurity conference outside Washington on Monday.
What they are seeking is people who are willing to take malicious code they provide and link it to something that people will click on -- like a picture of Britney Spears getting out of her car. These people then collect a fee for each 1,000 times that the malware is downloaded.
One site, for example, pays $180 for each 1,000 times that malware is downloaded onto a U.S. computer but less for computers elsewhere. It refuses to pay for any downloads to Russian computers, causing Stevens and others to strongly suspect that it, like other similar sites, are based in Russia.
"We pay your wages via the following systems: Fethard, WebMoney, Wire, e-gold, Western Union (WU), MoneyGram, Anelik and ePassporte, and PayPal," the site said.
Stevens said it was impossible to know how many computers were infected via these companies but put the number in the millions.
Security professionals in the audience for Stevens' presentation laughed at times, most likely at how blatant the web sites were. reuters
Two companies that are hiring -- at least on a contractor basis -- advertise online, said Kevin Stevens, a threat intelligence analyst for SecureWorks, who presented findings on the organizations at the Black Hat cybersecurity conference outside Washington on Monday.
What they are seeking is people who are willing to take malicious code they provide and link it to something that people will click on -- like a picture of Britney Spears getting out of her car. These people then collect a fee for each 1,000 times that the malware is downloaded.
One site, for example, pays $180 for each 1,000 times that malware is downloaded onto a U.S. computer but less for computers elsewhere. It refuses to pay for any downloads to Russian computers, causing Stevens and others to strongly suspect that it, like other similar sites, are based in Russia.
"We pay your wages via the following systems: Fethard, WebMoney, Wire, e-gold, Western Union (WU), MoneyGram, Anelik and ePassporte, and PayPal," the site said.
Stevens said it was impossible to know how many computers were infected via these companies but put the number in the millions.
Security professionals in the audience for Stevens' presentation laughed at times, most likely at how blatant the web sites were. reuters
Cyber breaches are a closely kept secret
Cybercriminals regularly breach computer security systems, stealing millions of dollars and credit card numbers in cases that companies keep secret, said the FBI's top Internet crimes investigator on Tuesday.
For every break-in like the highly publicized attacks against TJX Co (TJX.N) and Heartland Payment (HPY.N), where hacker rings stole millions of credit card numbers, there are many more that never make the news.
"Of the thousands of cases that we've investigated, the public knows about a handful," said Shawn Henry, assistant director for the Federal Bureau of Investigation's Cyber Division. "There are million-dollar cases that nobody knows about."
Companies that are victims of cybercrime are reluctant to come forward out of fear the publicity will hurt their reputations, scare away customers and hurt profits. Sometimes they don't report the crimes to the FBI at all. In other cases they wait so long that it is tough to track down evidence.
"Keeping your head in the sand on filing a report means that the bad guys are out there hitting the next guy, and the next guy after that," Henry said.
He said the cybercrime problem has gotten bigger over the past three years because hackers have changed their attack methods as companies have tightened up security.
"It's absolutely gotten bigger, yes, absolutely," he said.
That is because the Internet is rapidly growing as a tool for commerce. As it does, consumers and companies alike are exposing valuable data such as business plans, credit card numbers, banking information and Social Security numbers.
"There are hundreds of billions of dollars that traverse the Internet," he said.
Cybercriminals are now looking beyond large companies, which in the past 10 years have bolstered security on their networks using products from software companies including Symantec Corp (SYMC.O), McAfee Inc (MFE.N) and Trend Micro Inc (4704.T). Cisco Systems Inc (CSCO.O), International Business Machines Corp (IBM.N) and Websense Inc (WBSN.O) also sell products to protect computer networks. reuters
For every break-in like the highly publicized attacks against TJX Co (TJX.N) and Heartland Payment (HPY.N), where hacker rings stole millions of credit card numbers, there are many more that never make the news.
"Of the thousands of cases that we've investigated, the public knows about a handful," said Shawn Henry, assistant director for the Federal Bureau of Investigation's Cyber Division. "There are million-dollar cases that nobody knows about."
Companies that are victims of cybercrime are reluctant to come forward out of fear the publicity will hurt their reputations, scare away customers and hurt profits. Sometimes they don't report the crimes to the FBI at all. In other cases they wait so long that it is tough to track down evidence.
"Keeping your head in the sand on filing a report means that the bad guys are out there hitting the next guy, and the next guy after that," Henry said.
He said the cybercrime problem has gotten bigger over the past three years because hackers have changed their attack methods as companies have tightened up security.
"It's absolutely gotten bigger, yes, absolutely," he said.
That is because the Internet is rapidly growing as a tool for commerce. As it does, consumers and companies alike are exposing valuable data such as business plans, credit card numbers, banking information and Social Security numbers.
"There are hundreds of billions of dollars that traverse the Internet," he said.
Cybercriminals are now looking beyond large companies, which in the past 10 years have bolstered security on their networks using products from software companies including Symantec Corp (SYMC.O), McAfee Inc (MFE.N) and Trend Micro Inc (4704.T). Cisco Systems Inc (CSCO.O), International Business Machines Corp (IBM.N) and Websense Inc (WBSN.O) also sell products to protect computer networks. reuters
Monday, February 1, 2010
"Alarming" rise in cyberattacks at social networks: Sophos
There has been an "alarming" rise in spammers and hackers hunting for victims at online social networks, according to a report released Monday by computer security firm Sophos.
A "Social Security" investigation revealed an "explosion" of spam messages and nefarious software targeting users of social networks such as Facebook and Twitter.
"Computer users are spending more time on social networks, sharing sensitive and valuable personal information, and hackers have sniffed out where the money is to be made," said Sophos senior technology consultant Graham Cluley.
"Social networks and their millions of users have to do more to protect themselves from organized cybercrime, or risk falling prey to identity theft schemes, scams, and malware attacks."
Facebook last month announced an alliance with Internet security specialty firm McAfee to get members of the world's leading online social network to better defend their computers.
"Facebook is by far the largest social network -- and you'll find more bad apples in the biggest orchard," explained Cluley.
"The truth is that the security team at Facebook works hard to counter threats on their site -- it's just that policing 350 million users can't be an easy job for anyone." .smh.com.
A "Social Security" investigation revealed an "explosion" of spam messages and nefarious software targeting users of social networks such as Facebook and Twitter.
"Computer users are spending more time on social networks, sharing sensitive and valuable personal information, and hackers have sniffed out where the money is to be made," said Sophos senior technology consultant Graham Cluley.
"Social networks and their millions of users have to do more to protect themselves from organized cybercrime, or risk falling prey to identity theft schemes, scams, and malware attacks."
Facebook last month announced an alliance with Internet security specialty firm McAfee to get members of the world's leading online social network to better defend their computers.
"Facebook is by far the largest social network -- and you'll find more bad apples in the biggest orchard," explained Cluley.
"The truth is that the security team at Facebook works hard to counter threats on their site -- it's just that policing 350 million users can't be an easy job for anyone." .smh.com.
Study: Of All Breaches, Those Caused by Hacking Are the Costliest
The cost of data breaches rose slightly last year, but breaches resulting from computer hacking incurred by far the highest losses, according to a new report from privacy and data-security research firm Ponemon Institute LLC.
The average cost per compromised customer record rose to $204 in 2009 from $202 in 2008 and $138 as recently as 2005, according to Traverse City, Mich.-based Ponemon’s “2009 Annual Study: Cost of a Data Breach.” Some 24% of breaches were caused by placement of so-called malware or botnets or related criminal attacks on computer systems, double the 12% rate for such attacks in 2008. Forty percent of 2009’s breaches resulted from negligence, and 36% come from system glitches, according to the study.
The study, sponsored by Menlo Park, Calif.-based data-protection technology provider PGP Corp., is based on the actual breach experiences of 45 companies in 15 industry sectors. The firms agreed to complete detailed surveys about their breaches, including discovery, response, and effects on their businesses. Respondents included eight financial firms, eight retailers, five services firms, and four technology companies. None was identified specifically. Breaches affected 5,000 to more than 101,000 records. Forty-two percent of the breaches in the 2009 study involved mistakes by outsourcers.
Of the $204 overall loss per record, some $60 came from direct costs to find and fix the breach and resolve problems such as legal matters. Ponemon says direct costs rose in 2009 by $10 because of higher legal expenses. The other $144 consisted of indirect costs, including abnormal customer turnover. Indirect costs declined an estimated 5% in 2009 but breach-related customer churn still accounts for 40% of incident expenses, the report says.
Malicious attacks are the most costly, with resulting expenses of $215 per compromised record, the study says. That’s 39% higher than the $154 per-record breach expenses from negligence. Breaches from system glitches cost an average of $166 per compromised record.
Citing figures from the San Diego-based Identity Theft Resource Center, Ponemon noted that the number of reported breaches fell to 498 in 2009 from 657 in 2008. But the average cost per incident rose to $6.75 million last year from $6.65 million the year before.
Merchant acquirer Heartland Payment Systems Inc., which in January 2009 announced a data breach that a federal prosecutor later said may have compromised 130 million cards, apparently the biggest ever, was not part of the study. But Ponemon Institute chairman and founder Larry Ponemon tells Digital Transactions News by e-mail that, “For merchant processors, or any company … collecting, managing, and securing sensitive consumer information, the number-one lesson is, poor information security comes at a steep price. Given the rising dollar costs and the cost to reputation, we believe that more and more companies will begin to embrace security as a strategic competitive differentiator, which will ultimately make the cost that much greater in terms of lost business for those organizations that fail to address this issue seriously.” digitaltransactions
The average cost per compromised customer record rose to $204 in 2009 from $202 in 2008 and $138 as recently as 2005, according to Traverse City, Mich.-based Ponemon’s “2009 Annual Study: Cost of a Data Breach.” Some 24% of breaches were caused by placement of so-called malware or botnets or related criminal attacks on computer systems, double the 12% rate for such attacks in 2008. Forty percent of 2009’s breaches resulted from negligence, and 36% come from system glitches, according to the study.
The study, sponsored by Menlo Park, Calif.-based data-protection technology provider PGP Corp., is based on the actual breach experiences of 45 companies in 15 industry sectors. The firms agreed to complete detailed surveys about their breaches, including discovery, response, and effects on their businesses. Respondents included eight financial firms, eight retailers, five services firms, and four technology companies. None was identified specifically. Breaches affected 5,000 to more than 101,000 records. Forty-two percent of the breaches in the 2009 study involved mistakes by outsourcers.
Of the $204 overall loss per record, some $60 came from direct costs to find and fix the breach and resolve problems such as legal matters. Ponemon says direct costs rose in 2009 by $10 because of higher legal expenses. The other $144 consisted of indirect costs, including abnormal customer turnover. Indirect costs declined an estimated 5% in 2009 but breach-related customer churn still accounts for 40% of incident expenses, the report says.
Malicious attacks are the most costly, with resulting expenses of $215 per compromised record, the study says. That’s 39% higher than the $154 per-record breach expenses from negligence. Breaches from system glitches cost an average of $166 per compromised record.
Citing figures from the San Diego-based Identity Theft Resource Center, Ponemon noted that the number of reported breaches fell to 498 in 2009 from 657 in 2008. But the average cost per incident rose to $6.75 million last year from $6.65 million the year before.
Merchant acquirer Heartland Payment Systems Inc., which in January 2009 announced a data breach that a federal prosecutor later said may have compromised 130 million cards, apparently the biggest ever, was not part of the study. But Ponemon Institute chairman and founder Larry Ponemon tells Digital Transactions News by e-mail that, “For merchant processors, or any company … collecting, managing, and securing sensitive consumer information, the number-one lesson is, poor information security comes at a steep price. Given the rising dollar costs and the cost to reputation, we believe that more and more companies will begin to embrace security as a strategic competitive differentiator, which will ultimately make the cost that much greater in terms of lost business for those organizations that fail to address this issue seriously.” digitaltransactions
Report: Data Breach Costs On The Rise
The cost of a data breach rose slightly last year as malicious attacks and botnets increased in number, according to a report from the Ponemon Institute.
The annual "Cost of a Data Breach Survey," released Monday, said such incidents cost U.S. companies an average of $204 per compromised customer record in 2009, compared to $202 in 2008.
The average total organizational per-incident costs rose slightly in 2009 to $6.75 million, compared to an average per-incident cost of $6.65 million in 2008, despite an overall drop in the number of reported breaches. The total number of data breaches dipped in 2009 to 498, down from 657 in 2008, the study said, citing a report from the Identity Theft Resource Center.
Larry Ponemon, chairman and founder of the Ponemon Institute, said that customer churn rate comprised the "lion's share" of the costs for organizations following a data breach. Much of those costs were due to increased recruitment and marketing expenses incurred by companies due to an upsurge of customer attrition following a breach. "People do leave. It reduces the brand of an organization, and increases acquisition costs of new customers," he said. crn.com
The annual "Cost of a Data Breach Survey," released Monday, said such incidents cost U.S. companies an average of $204 per compromised customer record in 2009, compared to $202 in 2008.
The average total organizational per-incident costs rose slightly in 2009 to $6.75 million, compared to an average per-incident cost of $6.65 million in 2008, despite an overall drop in the number of reported breaches. The total number of data breaches dipped in 2009 to 498, down from 657 in 2008, the study said, citing a report from the Identity Theft Resource Center.
Larry Ponemon, chairman and founder of the Ponemon Institute, said that customer churn rate comprised the "lion's share" of the costs for organizations following a data breach. Much of those costs were due to increased recruitment and marketing expenses incurred by companies due to an upsurge of customer attrition following a breach. "People do leave. It reduces the brand of an organization, and increases acquisition costs of new customers," he said. crn.com
Subscribe to:
Posts (Atom)






.jpg)
