Thursday, October 15, 2009

Bracing for a New World

In a declining economy, Indian enterprises are waking up to a new world where Mobility, Virtualization and Cloud Computing technologies present new challenges and the employee is now the weakest link in the information security ecosystem

In October last year, Rajendrasinh Makwana, an IT contractor who worked in Fannie Mae (a US government-owned firm), was indicted for planting a logic bomb designed to wipe out data from the firm’s 4,000 servers. Makwana planted the logic bomb in the form of a malicious script embedded within a legitimate code. Had the malicious script managed to execute, it would have resulted in the company being shut down for a week. The reason for Makwana’s action—the company had fired him for a scripting error he made earlier. Angered, Makwana planted the malicious script on the day he was fired.


Makwana’s case is not an isolated one. For companies that feel the heat of the economic slowdown and decide to lay off staff, the ‘trusted’ employee could suddenly become a more potent threat than an external hacker.


This fact is supported by a 2008 FICCI-PwC report, in which a majority of the organizations surveyed believed that employees or former employees are a major source of security threats. Almost 47 percent of the organizations believed that employees were responsible for security incidents and 25 percent attributed them to former employees. Only 39 percent of the companies attributed negative security events to external hackers.


Virtual Threats
With the rise in virtualized environments, CIOs face a new level of complexity, as virtualization introduces another layer that needs to be secured. For example, when a hypervisor is compromised, all the virtual machines that run on the hypervisor will also be compromised.


“With modern virtualization technology, virtual machines can be easily cloned and installed on a different physical machine. The ability to go back to ‘snapshots’ of past images can inadvertently wreak havoc with the patch management process,” says Sunil Rawlani, Executive VP and Head, IT, HDFC Standard Life Insurance. Analysts also believe that a compromise of a single virtualized machine can infect all other virtual machines on a physical server.


While organizations have given employees laptops and smartphones as a means to improve their productivity, this also presents immense risks, as these devices carry critical business information. However, what is shocking is that the data on most of these devices is not encrypted. This can be a security disaster waiting to happen. Additionally, unlike IT assets which are managed by an IT asset management system, a mobile device management policy is still not in place for most organizations.


Wireless security is another weak area, and this has been proved by the increasing number of attacks on wireless networks. A survey by Deloitte Research in India revealed that around 86 percent of the wireless networks in the cities that were surveyed were vulnerable i.e. having no encryption or a low level of encryption which could be easily compromised. Thirty-seven percent of the networks surveyed were found to have no encryption. While weak encryption is the common culprit for security breaches, other security vulnerabilities in wireless networks are a result of mis-configured access points and outdated access point firmware.

Not so social
Social networking sites, which have become so popular with youngsters, are a nightmare for CIOs—especially when it comes to ensuring security. Agrees Rawlani, “Web 2.0 technologies when combined with our ‘work-from-anywhere’ lifestyle have begun to blur the lines between work and private life. Because of this psychological shift, people may inadvertently share information their employer would have considered sensitive.”


A recent survey on Web 2.0 usage in the workplace by vendor Websense highlights the emerging dangers of using social networking websites. The survey found out that in India, Web 2.0 is already pervasive in the workplace, with more than 70 percent of the organizations surveyed allowing access to wikis, and 40 percent allowing access to social networking websites such as Facebook. However, while more than 70 percent of these companies have URL filtering software, only 39 percent block Instant Messaging (IM) attachments, and only 41 percent of the respondents had a mechanism to detect embedded malicious code on trusted websites. This opens up potential doors for attackers to get a foothold into organizations, especially when you consider the fact that websites allowing user-generated content comprise the majority of the 50 most active distributors of malicious content on the Internet.


To tackle these challenges, anti-malware technologies too have grown in depth and sophistication. For example, Websense’s ThreatSeeker Network gives customers the ability to identify and classify spam posted as comments to forums, blogs or social networking sites. Comment traffic is automatically routed through a spam filtering service and every comment can be analyzed and given a ‘spam’ score. This improves the ability of enterprises to tackle spam on their blogs.


Similarly, RSA Security has a solution called ‘Adaptive Authentication.’ This solution monitors user behavior and assigns a unique risk score to the user’s activity. Whenever high-risk activities are triggered, the solution prompts the user for additional credentials. This solution is already in use in HDFC Bank, and has helped the bank reduce a huge number of phishing attacks.


Cloudy security
As more applications move to the cloud, security-related aspects will be put to the test, as increasing access points compound management challenges. Cloud Computing also highlights perceived issues that CIOs have in terms of data loss or data theft. “The key threats are in terms of the security of data at rest, compliance requirements due to outsourcing of data, recovery of data across the cloud in the event of an issue, and support for investigation of data within the cloud,” says Navin Agrawal, Executive Director, KPMG. Additionally, within the cloud, enterprises need to look at standard issues such as user access, authentication, privacy and the location where the data is stored.


It is also interesting to note that even as enterprises are worried about security issues in the cloud, service providers such as Trend Micro are leveraging the cloud for providing security-based services. For example, research indicates that more than 1,500 unique malware variants are generated every hour. If organizations fail to patch up fast enough, they will be extremely vulnerable to attacks. Trend Micro has responded to this situation by launching a cloud-based service, where the actual scanning is done in the cloud.


The new face of cyber threats
With a huge underground market for stolen credit cards, fraudsters are offering specialized toolkits and services. Thus, even common criminals, who have insufficient knowledge of sophisticated hacking techniques, can easily perpetuate online frauds. For example, in an annual online fraud report, RSA Security expects that underground services such as Centralized Trojan infections (offered via a pay-per-infection model) and All-in-One-Trojan packages (allowing people to purchase Trojan servers with corresponding botnets of infected computers) to grow at a fast pace.


Trojans have also become intelligent enough to launch new sophisticated modes of attack. For example, a study by RSA found out that hackers deployed variants of the Zeus Trojan and used the Jabber IM service to quickly transmit compromised user details. This means that as soon as a user account is compromised, it is quickly relayed in real time through IM to cyber criminals. Other techniques involve using Search Engine Optimization (SEO) methods to promote fake antivirus software. Hackers have also been quick to exploit social media such as Twitter to distribute malicious links. Twitter’s facility of providing anonymity by shortening the URL has also helped hackers to gain direct users to websites hosting malware or Trojans.


As is evident, security can never be a milestone. It is a continuously evolving journey, and enterprises have to constantly be on their guard against attacks that are quickly growing in sophistication and intent.

Source:- www.networkcomputing.in; By Srikanth RP

Job-seekers from North India fake it to make it

BANGALORE:

Recession does strange things to people. A trend recently observed shows a sharp increase in resume frauds in North India while South India and East India accounted for the lowest number of resume frauds. This uncomfortable fact was brought to light by a report released by a Background Screening and Risk Management consulting company.

The report ‘Background Screening Trends -- A Recession time study’ based on a survey which evaluated about 10,000 cases per month, by AuthBridge Research Services, evaluates the upward trend in resume embellishments as an aftermath of the recent economic meltdown.

North India accounted for:-

47% of the total discrepancies reported in country. Next in line was the Western part of the country with 32 % of discrepancies being reported from there. South and East India combined accounted for the lowest number, the report revealed.

“March saw the highest number of resume embellishments-16%

Interestingly, this was the month when the economy was at its worst,” the report said. The report pointed out that discrepancies related to previous employment were 74% of the total discrepancies of which 59% candidates lied about their tenure, designation, CTC or reporting manager.

According to the report, fake/ forged documents formed 69% of the total education-related discrepancies.
Maximum discrepancies were reported from ITeS, IT and BFSI sectors. Commenting on the report and its findings, Ajay Trehan, Chief Executive Officer, AuthBridge, said, “Job cuts, layoffs and salary cuts have been the key factors during recession instigating candidates to lie in resumes so as to bag the available job at any cost.” “The upward trend in resume frauds show that employers need to scrutinise candidate’s profile even more carefully and watch for fraudulent credentials, such as inflated or fictional employment history or educational degrees so as to secure them from the hazardous repercussions of unsafe hiring,” he added.

Rajeev Yadav, Senior Division Manager - HR, NIIT Technologies said, “While we have seen that there has been increasing number of fraud and other problems, the study has provided with factual data and it is now necessary for companies across the industry who are manpower intensive as well as that handle sensitive information to set up risk management systems in place.” The difference between the information provided by the job applicant and the information dug out by AuthBridge while conducting background checks, also known as discrepancy rate was significantly higher than normal during the peak recession period.

Source: www.expressbuzz.com ; By Jayadevan PK

Tuesday, October 13, 2009

Gone in nanoseconds: ID fraud too fast to control

One in five Australians have been victims of identity-related crime and 1.5 million people have had their credit cards illegally copied in the past year.
And so far this year, 188 Australian ATMs have been "compromised" by ATM skimming bandits who used devices to steal customer's PIN details.
Queensland Police have today hosted a National Identity Crime Symposium on the Gold Coast with police, academics and international guests discussing ways to combat identity-related fraud.
Professor Jonathan Rusch, of the United States Department of Justice, told the conference identity fraud was one of the fastest growing crimes in the world.
He said more than 1.2 million Australians have had their bank account details illegally accessed and almost the same number of people had had their personal mail stolen in the past year.
One fifth of the Australian population had been victims of identity fraud and 1.5 million people had their credit cards compromised in the past year, he said.
Professor Rusch said in the United Kingdom, one in six people were victims of identify fraud in 2007 and in the first half of 2009, identity fraud had risen by 74 per cent.
"Card not present" fraud, which included phone and internet purchases, amounted to £328 million last year, he said.
He said the digital age meant people’s personal information was travelling "in nano-seconds through the internet."
"Information flows faster than the ability to control that flow, in some cases the consequences can be catastrophic," he said.
The speed of criminal activity was also fast, he said, with 71 per cent of frauds associated with identity crime occurring in less than one week from the time the data was first stolen.
"Fraudsters are getting more sophisticated and using more attacks of opportunity whereever they can find data exposed," he said.
A recent research into convicted identity thieves found many did not understand the harm they caused their victims.
Professor Rusch said offenders saw it as an "easy, rewarding and relatively risk-free way for them to fund their personal lifestyles."
They also believed it was big corporations and credit card companies which suffered the loss, not individual victims, he said.
Professor Rusch said a particular problem for Australia was ATM skimming, with 188 ATMs in the past year compromised by criminals using skimming devices which can be used to detect ATM users’ PINs.
"Without realising as soon as you dip in your card and enter your PIN, you’ve unwittingly transmitted your information directly to the criminals who are monitoring that ATM," he said.
"They can move very quickly to counterfeit cards and run to other ATMs and start draining money out of your bank account at great speed."
The symposium will continue until Wednesday and include several guest speakers, including academics and private sector experts on identity-related fraud.
Source:- Brisbane Times

Monday, October 5, 2009

$80 MILLION PONZI SCAM - Even Friends Got Fooled

Automated teller machine

It sounded like a smart idea: investing in automated teller machines (ATMs) located in high-traffic retail locations around the country. The investors would recoup their money, plus an incredible 20-24 percent return, through the fees charged to the ATM customers. Seemed like a deal too good to pass up.

But investors should have done just that—because it was a fraud…a Ponzi scheme, to be more precise. The $80 million in investor funds raised over time weren’t used to purchase ATMs, they were used to fuel the ruse and line the pockets of the two masterminds behind the scheme.

So says a federal indictment unsealed in the Southern District of New York last week against Vance Moore, II and Walter Netschi, charged with wire fraud and conspiracy after an investigation by the FBI.

The scam. According to the indictment, Netschi and others convincingly sold the scheme to thousands of investors—mainly small private equity/hedge fund investment companies, small businesses, retirees, and even friends. Through his front company, Netschi would “sell” individual ATMs or groups of ATMs placed in areas with a lot of foot traffic—like convenience stores, gas stations, malls, and hotels.

Netschi then allegedly had the investors sign agreements with Moore’s “company” to service, process, and maintain the ATMs.

At first, investors were happy. Moore’s company allegedly sent them not only monthly financial statements listing transaction histories and fees for the ATMs, but it also wired them their share of the profits. (Little did investors know that these profits were coming not from ATM fees but from subsequent investors recruited by Netschi.)

Approximately 4,000 ATMs were supposedly purchased and serviced by Netschi and Moore, but in reality—according to the indictment—about 90 percent of these machines “sold” to investors either didn’t exist or were owned by other companies.

Then, the money to pay investors ran out—like it usually does in Ponzi schemes as they grow larger and larger and are unable to sustain themselves. For months, Netschi and Moore allegedly gave investors various explanations for the non-payments, blaming various banks and software glitches. They even went out and recruited more investors, said the indictment. But they couldn’t raise the funds they needed, and ultimately, an unhappy investor notified authorities.

And turnabout is fair play—last week’s indictment seeks $80 million in forfeiture from the alleged con artists.

How can you avoid being victimized by a Ponzi scheme? Here are a few tips:

  • Be careful of any investment opportunity that makes exaggerated earnings claims.
  • Exercise due diligence in selecting investments and the people with whom you invest—in other words, do your homework!
  • Make sure you fully understand the investment before you hand over your money.
  • Consult an unbiased third party, like an unconnected broker or licensed financial advisor, before investing.
  • Don’t be fooled into believing an investment is safe just because someone you know recommended it. So-called “affinity scams” are one of the favorite methods used to lure people into Ponzi schemes
Source: www.fbi.gov - 02/10/09

Friday, October 2, 2009

TECHNIQUES USED BY FRAUDSTERS ON SOCIAL NETWORKING SITES

TECHNIQUES USED BY FRAUDSTERS ON SOCIAL NETWORKING SITES


Fraudsters continue to hijack accounts on social networking sites and spread malicious software by using various techniques. One technique involves the use of spam to promote phishing sites, claiming there has been a violation of the terms of agreement or some other type of issue which needs to be resolved. Other spam entices users to download an application or view a video. Some spam appears to be sent from users' "friends", giving the perception of being legitimate. Once the user responds to the phishing site, downloads the application, or clicks on the video link, their computer, telephone or other digital device becomes infected.

Another technique used by fraudsters involves applications advertised on social networking sites, which appear legitimate; however, some of these applications install malicious code or rogue anti-virus software. Other malicious software gives the fraudsters access to your profile and personal information. These programs will automatically send messages to your "friends" list, instructing them to download the new application too.

Infected users are often unknowingly spreading additional malware by having infected Web sites posted on their Webpage without their knowledge. Friends are then more apt to click on these sites since they appear to be endorsed by their contacts.

Tips on avoiding these tactics:

  • Adjust Web site privacy settings. Some networking sites have provided useful options to assist in adjusting these settings to help protect your identity.
  • Be selective of your friends. Once selected, your "friends" can access any information marked as "viewable by all friends."
  • You can select those who have "limited" access to your profile. This is for those whom you do not wish to give full friend status to or with whom you feel uncomfortable sharing personal information.
  • Disable options and then open them one by one such as texting and photo sharing capabilities. Users should consider how they want to use the social networking site. If it is only to keep in touch with people then perhaps it would be better to turn off the extra options which will not be used.
  • Be careful what you click on. Just because someone posts a link or video to their "wall" does not mean it is safe.

Those interested in becoming a user of a social networking site and/or current users are recommended to familiarize themselves with the site's policies and procedures before encountering such a problem.

Each social networking site may have different procedures on how to handle a hijacked or infected account; therefore, you may want to reference their help or FAQ page for instructions.

Source:- Internet Crime Complaint Center (IC3)

Thursday, October 1, 2009

RBI for info pool to fix frauds

Mumbai :

In a bid to tackle rising frauds in the banking system, the Reserve Bank of India (RBI) has asked banks to build up a data or information pool of large-value frauds and analyse them periodically. This may act as a knowledge repository for policy responses.

The central bank has also said that in the matter of fraud investigation, banks may take immediate steps to identify staff with proper aptitude and provide necessary training to them in forensic audit so that only such skilled staff is deployed for investigation of large-value frauds.

It has been observed that the trend is more disquieting in retail segment, especially in housing and mortgage loans, credit card dues and internet banking.

Moreover, it is a matter of concern that instances of frauds in the traditional areas of banking such as cash credit, export finance, guarantees, and letters of credit remain unabated, the RBI said.

Banks are also advised to initiate necessary action at their end at the earliest.

“Banks may, with the approval of their respective boards, frame internal policy for fraud risk management and fraud investigation functions, based on the governance standard relating to the ownership of the function and accountability for malfunctioning of the fraud risk management process in their banks,” the RBI said.

Given the thin line of difference between serious wrongdoings and frauds, the bank should immediately put in place an adequately enabled and efficient ‘internal oversight framework’ that can prevent the wrongdoings and take punitive measures against the wrongdoers, the RBI said.

The Board for Financial Supervision (BFS) has felt the chief executive officers (CEOs) of the banks must provide singular focus on the “Fraud Prevention & Management Function” to enable effective investigation and prompt accurate reporting to appropriate regulatory and law enforcement authorities, including the Reserve Bank.

The board has also observed that in terms of higher governance standards, the fraud risk management and fraud investigation function must be owned by the bank’s CEO, its audit committee of the board and the special committee of the board, at least in respect of high value frauds.

Accordingly, they should own responsibility for systemic failure of controls or absence of key controls or severe weaknesses in existing controls which facilitate exceptionally large-value frauds and sharp rises in frauds in specific business segments leading to large losses for the bank.

Source: www. financialexpress.com

Wednesday, September 30, 2009

ICAI wings clipped over Satyam scam


The finance committee will now clear spending on infrastructure

Sangeeta Singh

New Delhi: The fraud perpetrated by Satyam Computer Services Ltd’s founder B. Ramalinga Raju has claimed some collateral damage: the apex body of accountants in the country, and its current president Uttam Prakash Agarwal.

The government has, in recent weeks, tightened its control over the Institute of Chartered Accountants of India (Icai) diluting Agarwal’s own powers in the process.

The move comes ahead of crucial elections to the body founded in 1949 and which regulates the functioning of at least 150,000 chartered accountants who sign off on the financial statements of companies—a sort of first line of defence against any financial misconduct by management or promoters.

Some of the government’s actions are seen by two people, an Icai council member and an official at the ministry of corporate affairs (MCA), as a reaction to Agarwal’s handling of the Satyam scandal, an allegation Agarwal denies.

Icai’s council is the institute’s core decision-making unit.

One of the charges against Agarwal is that he has been “soft” on S. Gopalakrishnan, a partner at Price Waterhouse, which audited Satyam’s books, and now in jail as his role in the Satyam scandal is investigated. “The allegation that I have gone slow on Gopalakrishnan or produced a weak report is absolute rubbish,” Agarwal said.

investigated. “The allegation that I have gone slow on Gopalakrishnan or produced a weak report is absolute rubbish,” Agarwal said.

The most significant rule change, approved by Icai’s finance committee last week, requires all financial issues at Icai to be now cleared consensually by members of the panel, which has three government nominees. Previously, the president of Icai, the fourth member of the committee, used to take these decisions on his own without too much interference by government nominees. The fifth member of the panel is the body’s vice- president. “It has been decided that while (the) finance committee will not dig into expenditure that has been made in the past, in future, all finance-related matters of Icai will come to the finance committee; spending on infrastructure such as on Icai buildings across the country and events will also need to be cleared by the committee,” said a person familiar with the decision made by the finance committee who did not want to be identified.

This person also added that only a deviation of 20% from the proposed expenditure would be tolerated. Mint couldn’t independently ascertain whether there have been any significant infrastructural investments made by Icai in recent years and whether the projects concerned, if any, cost more than initial estimates.

The committee’s decision comes in the wake of an email sent by a government nominee on Icai’s council and Supreme Court lawyer O.P. Vaish to Agarwal on 18 August that suggested discussing the issue related to financial decisions and others at an Icai council meeting the following day. Mint has reviewed the mail, but couldn’t ascertain the status of the other points raised by Vaish.

Vaish himself couldn’t be reached for comment.

The finance committee controls the institute’s purse strings and oversees its expenditure. The audit committee is in charge of Icai’s reporting process and also recommends the appointment and removal of statutory auditors for companies.

There are eight government nominees in Icai’s council, besides 32 chartered accountants from across India who are elected to the council every three years. The government nominees include Krishna Kant, retired chief commissioner of customs and central excise; R. Sekar, commissioner of customs; K.P. Sasidharan, director general (commercial), office of CAG (Comptroller and Auditor General of India); Renuka Kumar, joint secretary, MCA; and Vaish. Sekar, Kant and Sasidharan are included in the reconstituted finance committee and the last named has been made chairman of the audit committee.

Happenings at Icai are related to the Satyam scandal that blew into the open after the company’s founder-chairman B. Ramalinga Raju confessed in January to having fudged the company’s books over the years by at least Rs7,136 crore.

“One of the key questions we sought to address after the Satyam scandal was ‘Who will regulate the regulator?’” said a second person familiar with the developments at Icai, who too did not want to be identified.

Meanwhile, Agarwal said at a Friday meeting of Icai’s council that MCA director Jaikant Singh had written a letter to the effect that Icai’s president, vice-president and council members should steer clear of all policy decisions and press statements under a code of conduct ahead of the institute’s elections due in December. Such powers have been vested with T. Karthikeyan, Icai’s secretary.

“This is unprecedented and shows lack of faith in the president by the ministry (in Agarwal),” said the Icai council member mentioned in the first instance, and who spoke on condition of anonymity.

In press statements issued immediately after he visited Gopalakrishnan of Price Waterhouse in jail in March, Agarwal had said that “prima facie Gopalakrishnan is not guilty”. Gopalakrishnan has served on the council of Icai.

“It was only last month that Gopalakrishnan was removed from several committees of the council and replaced by government nominees,” said the same council member.

Agarwal, however, would appear to have changed his stance on Gopalakrishnan. On Monday, he said the auditor was prima facie guilty. “The disciplinary committee (of Icai) also found four auditors from Price Waterhouse, Bangalore, S. Gopalakrishnan, Srinivas Talluri, P. Shiva Prasad and C.H. Ravindranath prima facie guilty of professional misconduct,” he told PTI. The council member also found fault with Agarwal’s report on how Icai was handling the issue. This report was submitted to MCA.

The report “is a mere reproduction of the charge sheet filed by CBI (Central Bureau of Investigation) and SFIO (Serious Frauds Investigation Office, part of MCA),” said the member. An MCA official who did not want to be identified declined to comment on the report itself because it is being reviewed, but said, “Agarwal has acted in an immature manner in many ways.” He added that the ministry would prefer to see “matters resolved within (Icai’s) council”.

Under the Chartered Accountants Act, 1949, the ministry has powers to direct the institute. The official claimed that minister of corporate affairs Salman Khursheed, too, was unhappy with the goings-on at Icai and had been giving its functions a miss.

Mint couldn’t independently verify this. Khursheed could not be reached for comment.

Some of Agarwal’s colleagues have also raised charges of financial impropriety against him.

In an open letter, a copy of which has been reviewed by Mint, Sunil Talati, president of Icai in 2007-08, has claimed that there have been large amounts spent unnecessarily.

Agarwal dismissed these allegations. “Since council elections are round the corner, people are trying to defame me,” he said. He added that the government had cleared the institute’s accounts till March without raising any objections. “It is easy to write open letters, but council members should prove where I went wrong.”

Source:- Live Mint