Showing posts with label Attacks. Show all posts
Showing posts with label Attacks. Show all posts

DHS Guidance to Prevent Cyber Attacks

DHS Guidance to Prevent Cyber Attacks

The US Department for Homeland Security (DHS) unveiled new guidance on Monday designed to improve software security in the face of the growing problem of cyber attacks.

Central to the guidance to prevent cyber attacks is a list of 25 programming errors that enable the most serious hacks to occur - and advice on how to avoid them.

It released a list of software vulnerabilities called the Common Weakness Enumeration and set up a scoring system and analysis framework which organizations can use to measure and assess the threat level posed to them by hackers.

The DHS worked with a number of security consultancies, research organizations and private companies to compile the study.

Noting that human errors in programming are the cause of most attacks, the DHS said businesses should take heed of the advice and improve their software security, investing in far more superior and secure software protection systems. It also called for better training and education for software programmers.

Common Weakness Enumeration

At the top of the Common Weakness Enumeration, the list of 25 top security software vulnerabilities, was SQL injection which tricks systems into revealing secure information on databases to outsiders.

Mitre, the federal research laboratory which was contracted by the DHS to investigate the software security issue, said this flaw lay behind many of the recent high-profile hacks that led to organizations like Citigroup, Sony, the IMF and public agencies losing secure data.

The DHS intends the Common Weakness Enumeration and the accompanying scoring system to be a standard against which companies can measure and assess their security framework, and from these results take remedial action. It hopes the guidance - which is voluntary - will spur industry into making improvements.

Alan Peller from SANs, a consultancy involved in the DHS' work, said better quality software programming was the only way in which to really stop damaging cyber attacks.

"The only possible defense is to stop the error from being in the software in the first place," he told the Washington Post.

The Common Weakness Enumeration website can be accessed here:
http://cwe.mitre.org/

Further resources:

Computer Security 

Network Security Software


View the original article here

More Cyber Attacks Against Government In 2010

Cyber attacks against the US federal government rose by nearly 40 percent last year, reports the Federal times.

The Office of Management Budget's annual report on the federal cybersecurity effort showed that there were no fewer than 41,776 cyber attacks on government systems during 2010. This was up from the 30,000 recorded the previous year, a rise of 39 per cent.

The figures were released by the Department of Homeland Security (DHS) U.S. Computer Emergency Readiness Team (US-CERT).

Chris Ortman, DHS spokesman, said that the DHS "anticipates that malicious cyber activity will continue to become more common, more sophisticated and more targeted - and range from unsophisticated hackers to very technically competent intruders using state-of-the-art techniques."

Out of the total number of cyber attacks 12,864 were classified as malicious. Another 11,336 are under investigation, with unauthorized access, denial of service attacks, improper usage, scans probes and attempted access making up the remainder. Phishing was the major threat, with reported 56,579 attacks. There were 11,001 reports of attacks by trojan worms and viruses.

OMB's report said that particular cyber security threats for government were attacks exploiting so-called "zero-day", or unknown, vulnerabilities in software. The report said the "exploit codes" used to undertake such attacks are often made public through the internet.

The report said government cyber security is let down by the fact that two-thirds of federal are not yet continuously monitoring their networks. The report said 8 per cent had no monitoring systems in place at all.

However, the report also praised federal government's response to the growing cyber security threat by saying that agencies are now changing their policies to implement the Federal Information Security Management Act (FISMA) which lays down standards and policies about how agencies should deal with information security.

Last year also saw the introduction of a security threat reporting metric called Cyberscope, which aims to create a picture of how agencies are meeting their security obligations. During fiscal year 2011 a management model called CyberStat will be introduced across federal government which will allow agencies to examine security metrics and develop security plans to respond to any threats.

Further resources:

IT Security


View the original article here

More Cyber Attacks Against Government In 2010

Cyber attacks against the US federal government rose by nearly 40 percent last year, reports the Federal times.

The Office of Management Budget's annual report on the federal cybersecurity effort showed that there were no fewer than 41,776 cyber attacks on government systems during 2010. This was up from the 30,000 recorded the previous year, a rise of 39 per cent.

The figures were released by the Department of Homeland Security (DHS) U.S. Computer Emergency Readiness Team (US-CERT).

Chris Ortman, DHS spokesman, said that the DHS "anticipates that malicious cyber activity will continue to become more common, more sophisticated and more targeted - and range from unsophisticated hackers to very technically competent intruders using state-of-the-art techniques."

Out of the total number of cyber attacks 12,864 were classified as malicious. Another 11,336 are under investigation, with unauthorized access, denial of service attacks, improper usage, scans probes and attempted access making up the remainder. Phishing was the major threat, with reported 56,579 attacks. There were 11,001 reports of attacks by trojan worms and viruses.

OMB's report said that particular cyber security threats for government were attacks exploiting so-called "zero-day", or unknown, vulnerabilities in software. The report said the "exploit codes" used to undertake such attacks are often made public through the internet.

The report said government cyber security is let down by the fact that two-thirds of federal are not yet continuously monitoring their networks. The report said 8 per cent had no monitoring systems in place at all.

However, the report also praised federal government's response to the growing cyber security threat by saying that agencies are now changing their policies to implement the Federal Information Security Management Act (FISMA) which lays down standards and policies about how agencies should deal with information security.

Last year also saw the introduction of a security threat reporting metric called Cyberscope, which aims to create a picture of how agencies are meeting their security obligations. During fiscal year 2011 a management model called CyberStat will be introduced across federal government which will allow agencies to examine security metrics and develop security plans to respond to any threats.

Further resources:

IT Security


View the original article here

Related Posts Plugin for WordPress, Blogger...