Cyber-Ark Predicts: What’s Next on the Privileged Horizon
Posted on December 15, 2011 by Andrey Dulkin
Over the past year we’ve witnessed several spectacular attacks that demonstrated just how dangerous cyber criminals have become. These attacks have emphasized that a narrow focus on protecting against the insider threat is short-sighted and that more preventative approaches are needed to guard against external, highly targeted and persistent attacks that focus on high value information such as customer data and intellectual property. In taking stock of the threat landscape and emerging IT trends, we’ve summarized three key areas that we think will evolve significantly in the coming year, both in terms of technology innovation and risk.
Targeted Attacks: Preventative Protection on the Rise
As an industry, we’ve seen attacks move from opportunistic to increasingly sophisticated and targeted (think Stuxnet), with privileged access rights as a consistently – and perhaps increasingly – popular attack vector. Privileged accounts have proven to be a ‘sweet spot’ for attackers because of the broad, often anonymous access they provide to high value targets. However, many organizations are still in the early stages of identifying and solving privileged account weaknesses, including those caused by hard-coded passwords, which provides attackers with an extended window of opportunity.
That said, in the coming year we strongly believe that there will be a rise in more preventative approaches to protecting privileged accounts, including better isolation, access control and activity recording. This is due in part to greater awareness, increasing regulations and adoption of best practices, which are all driving significant growth for the privileged identity management market as a whole, and ultimately will help drive down the popularity of privileged accounts as an attack mechanism.
As strong indicators for the increasing need for more proactive privileged account management, consider that as a result of the changing threat landscape that the SANS Institute announced a major update to its 20 Critical Controls earlier this year. The 20 Critical Controls is a prioritized baseline of information security measures designed to provide continuous monitoring to better protect government and commercial computers and networks from cyber attacks. Several are directly related to privileged accounts: #8 Controlled Use of Administrative Privileges; #9 Controlled Access Based on the Need to Know and #11 Account Monitoring and Control.
Similarly, in the most recent NIST 800-53 publication that provides the recommended security controls for federal information systems and organizations, there is an emphasis establishing a proactive, preventative approach to privileged account management to achieve FISMA compliance.
SCADA Systems Under Attack: Vulnerabilities Continue to Put Critical Infrastructure at Risk
From weapons systems and water pumps to prison gates, systems not previously considered vulnerable to attack showed up in news headlines over past year. Those attacks have generated visibility for the fact that many of those systems were not designed with security in mind. Because of the hard-coded or weak/rarely changed passwords in tools like programmable logic controllers or SCADA software, those targets have become accessible to attackers, potentially putting critical infrastructure at risk.
With repeated attacks on the horizon, and building awareness, we expect that in 2012 there will be a notable increase in research dedicated to examining how hardware can be attacked by software, and the use of code to execute attacks particularly in the energy and utilities space. One early indicator that more research and solutions are needed may be statements made earlier this year by the U.S. Department of Homeland Security that said it was reevaluating whether it makes sense to warn the public about all of the security failings of industrial control system (ICS) and SCADA software – considering re-categorizing design flaws vs. security holes.
One of the main challenges with SCADA systems is that even when knowing about specific vulnerabilities, the cycles to fix them are so slow that it often makes more sense to try and keep the vulnerability confidential so attackers won’t exploit it during the lengthy repair period (remember “security by obscurity,” this of course will not be a long term strategy).
Private Clouds: Hypervisor Weaknesses Exposed
While some hesitancies around public cloud infrastructure may still exist, infrastructure changes resulting from rapid private cloud adoption could result in new risks, the scope of which we may not be fully aware of, yet, organizations will be expected to proactively protect against. For example, in a private cloud scenario, a virtual machine can sit on multiple servers or be accessible through multiple hosting centers. A systems administrator may know the virtual machine is accessible, but it’s difficult to know who has access to it, when it was accessed, or what was done once access was achieved. The hypervisor provides some of that much-needed control, but at the same time becomes an attractive target for attack. In 2012, protecting against hypervisor threats will quickly become an IT security priority, and, as we achieve greater maturity in the virtualization space, we could potentially see the cost efficiencies of virtualization take a second seat behind increased risk. We will also see IT security teams taking a more significant role in the initial build-out and deployment of private clouds to initiate much-needed proactive security infrastructure.
What are your thoughts on these 2012 trends to watch? Do you have some of your own to share?
IT Security Rewind – Week of November 28
Posted on December 5, 2011 by Josh Arrington
Returning from a holiday break is never easy, so if you were slightly neglectful to your industry news this week don’t fret – we’ve got it covered. It may have been a week of turkey hangovers for some of us, but the IT industry was busy reporting end-of-year recaps, forecasts for 2012 and of course, breaking news: Here is our summary of this week’s hottest stories.
Looking to achieve a life of “privilege” as an IT security pro? InformationWeek posted its annual “Best Paying IT Security Jobs In 2012” article and guess what? Security professionals can expect salaries to increase by an average of 4.5% in 2012—not bad in such a tumultuous economy. If you are a security professional in a midlevel/ senior role you are in a great position as demand is high. Supply, however, remains a different matter. Robert Half Technology said it expects to see “an abundance of positions and a shortage of skilled candidates.” As expected, the article also reported demand would soon increase for people who could manage “privileged identity management.”
Cyber crime linked to terrorism – In far more serious news, the FBI has revealed that four hackers were arrested in the Philippines last week in connection with an organized attack on the clients of U.S. telecommunications giant AT&T. Law enforcement officials believe the suspects were employed by the terrorist group Jemaah Islamiyah, which has been linked to numerous bombing attacks. According to Reuters, the FBI claims that AT&T’s customers were the targets of the hackers and were not the carriers themselves. An anonymous source reportedly added that the hackers breached the phone systems of AT&T customers and made calls to expensive international premium-rate services.
Water-pump hack pumped with errors – The SCADA hack that resulted in a water pump being destroyed has proven to be false – Wired reported this week that a contractor who was supposed to work on the system logged in according to permissions during a vacation trip to Russia, which was misconstrued as an outside hack. In truth, the water pump simply burned out, as pumps are wont to do, and a government-funded intelligence center incorrectly linked the failure to an internet connection from a Russian IP address months earlier.
That about wraps it up for this week – we’d love to hear your thoughts on this week’s happenings – leave your comments here…
Returning from a holiday break is never easy, so if you were slightly neglectful to your industry news this week don’t fret – we’ve got it covered. It may have been a week of turkey hangovers for some of us, but the IT industry was busy reporting end-of-year recaps, forecasts for 2012 and of course, breaking news: Here is our summary of this week’s hottest stories.
Looking to achieve a life of “privilege” as an IT security pro? InformationWeek posted its annual “Best Paying IT Security Jobs In 2012” article and guess what? Security professionals can expect salaries to increase by an average of 4.5% in 2012—not bad in such a tumultuous economy. If you are a security professional in a midlevel/ senior role you are in a great position as demand is high. Supply, however, remains a different matter. Robert Half Technology said it expects to see “an abundance of positions and a shortage of skilled candidates.” As expected, the article also reported demand would soon increase for people who could manage “privileged identity management.”
Cyber crime linked to terrorism – In far more serious news, the FBI has revealed that four hackers were arrested in the Philippines last week in connection with an organized attack on the clients of U.S. telecommunications giant AT&T. Law enforcement officials believe the suspects were employed by the terrorist group Jemaah Islamiyah, which has been linked to numerous bombing attacks. According to Reuters, the FBI claims that AT&T’s customers were the targets of the hackers and were not the carriers themselves. An anonymous source reportedly added that the hackers breached the phone systems of AT&T customers and made calls to expensive international premium-rate
Returning from a holiday break is never easy, so if you were slightly neglectful to your industry news this week don’t fret – we’ve got it covered. It may have been a week of turkey hangovers for some of us, but the IT industry was busy reporting end-of-year recaps, forecasts for 2012 and of course, breaking news: Here is our summary of this week’s hottest stories.
Looking to achieve a life of “privilege” as an IT security pro? InformationWeek posted its annual “Best Paying IT Security Jobs In 2012” article and guess what? Security professionals can expect salaries to increase by an average of 4.5% in 2012—not bad in such a tumultuous economy. If you are a security professional in a midlevel/ senior role you are in a great position as demand is high. Supply, however, remains a different matter. Robert Half Technology said it expects to see “an abundance of positions and a shortage of skilled candidates.” As expected, the article also reported demand would soon increase for people who could manage “privileged identity management.”
Cyber crime linked to terrorism – In far more serious news, the FBI has revealed that four hackers were arrested in the Philippines last week in connection with an organized attack on the clients of U.S. telecommunications giant AT&T. Law enforcement officials believe the suspects were employed by the terrorist group Jemaah Islamiyah, which has been linked to numerous bombing attacks. According to Reuters, the FBI claims that AT&T’s customers were the targets of the hackers and were not the carriers themselves. An anonymous source reportedly added that the hackers breached the phone systems of AT&T customers and made calls to expensive international premium-rate services.
Water-pump hack pumped with errors – The SCADA hack that resulted in a water pump being destroyed has proven to be false – Wired reported this week that a contractor who was supposed to work on the system logged in according to permissions during a vacation trip to Russia, which was misconstrued as an outside hack. In truth, the water pump simply burned out, as pumps are wont to do, and a government-funded intelligence center incorrectly linked the failure to an internet connection from a Russian IP address months earlier.
That about wraps it up for this week – we’d love to hear your thoughts on this week’s happenings – leave your comments here…
services.
Water-pump hack pumped with errors – The SCADA hack that resulted in a water pump being destroyed has proven to be false – Wired reported this week that a contractor who was supposed to work on the system logged in according to permissions during a vacation trip to Russia, which was misconstrued as an outside hack. In truth, the water pump simply burned out, as pumps are wont to do, and a government-funded intelligence center incorrectly linked the failure to an internet connection from a Russian IP address months earlier.
That about wraps it up for this week – we’d love to hear your thoughts on this week’s happenings – leave your comments here…
Recent Posts
- Excessive Admins and Privileged Security – Part II
- Excessive Admins and Privileged Security – Part I
- Grossly Underestimating the Privileged Account Security Problem Part 3: Automating Privileged Account Management and Cyber-Ark DNA™ (Discovery & Audit)
- Google’s Insecurities
- Grossly Underestimating the Privileged Account Security Problem Part 2: Defining Privilege with Cyber-Ark CMO, John Worrall
“The Compromise of Privileged Accounts was a Crucial Factor in 100% of APTs”: CyberSheath Releases the First APT/Privileged Account Research Report
Posted on April 24, 2013
Worried About Your Next Audit? Advanced Threats? Get to Know Your Privileged Accounts
Posted on April 1, 2013
Protecting Privileged Accounts can be the Difference Between “Managing” and “Securing” File Transfers
Posted on January 10, 2013
Copyright 2013 Cyber-Ark Software - All Rights Reserved
