Rise in Chinese-funded acquisitions could trigger more hurdles: By Ellyne Phneah , ZDNet Asia on May 22, 2012 (6... http://t.co/L4QzDq3H
14 minutes ago by LocalMobile911 on twitterZDNet is available in the following editions:
E-mail vigilance and multi-layer defense can ward off spear-phishing and advanced persistent threats, say security experts, who believe recent RSA breach is a one-off.
victor keong, graham titterington, science and technology, asia, technology, spam email, computer security, computer technology, paul ducklin, kpmg llp
The recent breach suffered by RSA was a "one-off compromise" that was hard to detect, note security experts, who renewed calls for organizations to exercise greater e-mail vigilance and multi-layer "defense in depth" protection.
Earlier this week, the security vendor revealed in a blog post that spear-phishing, a form of targeted phishing attack, was employed by attackers to carry out the first level of intrusion. Cybercriminals successfully stole information related to the SecurID authentication token in the attack, which was first announced last month.
RSA said cybercriminals sent two different e-mail messages containing an Excel attachment to two groups of unsuspecting employees over a two-day period, with the topic "2011 Recruitment Plan". Uri Rivner, head of new technologies in consumer identity protection at RSA, explained in the blog post that the file exploited a hole in Adobe Flash to install a Trojan that allowed the attacker to remotely take control of the computer.
The security division of EMC labeled the attack an advanced persistent threat (APT), similar to the Stuxnet and Operation Aurora incidents.
Vigilance from users, organizations
Commenting on the RSA breach, Paul Ducklin, Sophos' head of technology for the Asia-Pacific region, stressed that users need to be more vigilant about their e-mail habits.
Trusting Web links and e-mail instructions without much thought, he pointed out, is akin to inviting a stranger into one's home. "You open the door, the stranger has no identification or authorization. You didn't invite them, yet they're asking you to go to your home computer and do exactly the same things that the spear-phisher asked online.
Would you be prepared to follow their instructions, just because they were well-dressed, polite and claimed to know you?" he questioned in an e-mail interview with ZDNet Asia.
While RSA has not revealed what was comprised, talk was rife that databases containing unique numbers to generate one-time passwords for each SecureID token, had been accessed by the hackers. These passcodes, which are derived from a blend of a "secret seed" and the time of day, are used in two-factor authentication. About 40 million of the hardware token has been deployed globally, while 250 million software versions are in use.
Ducklin believes it is mere speculation that these numbers have been stolen.
Victor Keong, partner for Performance and Technology at KPMG Singapore, noted in an e-mail that token users should only be worried if the RSA token-generated codes are their only means of authentication.
"The ability to predict token codes should not be underestimated," he said. "However, despite the information the attackers might have stolen from RSA, an attacker would still have to overcome a few more hurdles, before an attack can be successful. They would need to know either a sequence of past token codes, or the serial number of the physical token."
An industry expert, however, told ZDNet Asia's sister site CNET that the algorithm mapping the serial number of a token to the seed was stolen. Chris Wysopal, CTO at application security firm Veracode, added that "the serial numbers used by an organization might not be well protected."
Ovum's principal analyst Graham Titterington added in an e-mail interview: "I believe that RSA has taken action to replace the affected seeds and so the vulnerability should be short lived."
Layered approach to security
KPMG's Keong also noted that such attacks are usually "disguised" and victim enterprises are unaware until actual loss is suffered.
"This is often the biggest issue with APT. Most victims do not know when an attack has occurred until they have suffered some form of a loss, either financial or privileged information leakage," he explained.
Ovum's Titterington concurred, adding that enterprises can use security information and event management (SIEM) products as an alert system. Blocking or detection of improper movement of data can be achieved with data leakage prevention products but are not easy, he said.
He recommended that RSA customers check their system logs for unusual system accesses during the period that the seeds were compromised, if they suspect that their data might be breached.
When quizzed on the feasibility of alternative security measures such as additional firewalls and tokens for virtual private network (VPN) implementation, Titterington dismissed them as "the wrong emphasis".
He argued: "Tokens can get compromised and lost. We have too many firewalls. We need a more agile approach to defending against threats."
Sophos' Ducklin advocated a "defense-in-depth" strategy to provide guard against spear-phishing and APTs."If the company practises multiple levels of protection and security, then it becomes much more difficult for outsider to carry on their attacks without triggering some sort of alarm at some point."
"A well-protected organization has many defense points. A good e-mail security gateway, and a sensible e-mail policy, might have blocked the unusual attachment in the first place," he explained.
Keong from KPMG added that security vendors should also beware of APTs going forward.
"If RSA was successfully compromised via APT, there is a high probability that similar attempts at other security software companies will also occur," he said.
Rise in Chinese-funded acquisitions could trigger more hurdles: By Ellyne Phneah , ZDNet Asia on May 22, 2012 (6... http://t.co/L4QzDq3H
14 minutes ago by LocalMobile911 on twitterKodak loses patent ruling against Apple, RIM - ZDNet Asia http://t.co/O7P8U2Ya
14 minutes ago by PatentWire on twitterRise in Chinese-funded acquisitions could trigger more hurdles - ZDNet Asia http://t.co/WJCfhWLs
14 minutes ago by JapanTechnology on twitterKodak loses patent ruling against Apple, RIM. http://t.co/N1j7aZ6o
29 minutes ago by zdnetasia on twitterRise in <b>Chinese</b>-funded acquisitions could trigger more hurdles http://t.co/0pXBS1HR
1 hour ago by GeorgeHAllenGA on twitterRise in Chinese-funded acquisitions could trigger more hurdles: By Ellyne Phneah , ZDNet Asia on May 22, 2012 (6... http://t.co/W3SOdw2c
1 hour ago by MergeAcquire on twitterRT @zdnetasia: CFOs increasingly involved in IT investment decisions. http://t.co/8QrfwOSb
1 hour ago by 666hellscream on twitterCFOs increasingly involved in IT investment decisions http://t.co/XD1LerFq via @zdnetasia #PrivateCloud #SC2012 #CAPEX
1 hour ago by HarishAitharaju on twitterRise in Chinese-funded acquisitions could trigger more hurdles. http://t.co/VC3G3m3o
1 hour ago by zdnetasia on twitterRT @zdnetasia: Rise in Chinese-funded acquisitions could trigger more hurdles. http://t.co/VC3G3m3o
1 hour ago by wrikent3500 on twitterSo much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...
1 hour ago by y15822137359 on 5 SaaS adoption speed bumps to avoidRise in Chinese-funded acquisitions could trigger more hurdles - ZDNet Asia: Rise in Chinese-funded acquisitions... http://t.co/bZaAQnRL
1 hour ago by MandAWorldwide on twitterRise in Chinese-funded acquisitions could trigger more hurdles http://t.co/mIsuZjnU http://t.co/erFX4aVv #arcavir
1 hour ago by V_RaV on twitterhttp://t.co/VNaZtseV Rise in Chinese-funded acquisitions could trigger more hurdles: "Cash r... http://t.co/N0gZZEdR http://t.co/wiqY9ktt
1 hour ago by RavtachSolution on twitterRise in Chinese-funded acquisitions could trigger more regulatory clearance issues overseas http://t.co/cvLSpTwo #in
1 hour ago by EllyZDNetAsia on twitterI reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...
1 day ago by wykoong on Gartner: Mobile CRM gives better ROI than socialThis video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...
1 day ago by TradeBrother on A quick fill handle trick for Microsoft Excelwaiting...
3 days ago by eapete on What should count in a company's market value?Boy, you've opened a can of worms now.
Wait for the rants & raves.
I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...
4 days ago by wykoong on Drop the egos, copy ideas, then innovateEchelon 2012 - The Awesomer Tech Event in Asia
Echelon 2012 – SEA’s longest running tech startup event goes Awesomer. Catch 50 of Asia’s most promising startups & over 40 international speakers on June 11-12.
Startup Asia Jakarta showcases new product-ready tech startups. Plus: hackathon, exhibition, and speakers. Use promo code CBSi50 for 50% discount.
ZDNet Asia Intelligent Singapore video series
Featuring inteviews with CXOs who define "intelligence" in their markets and reveal how their companies drive business efficiencies through ICT.