Showing posts with label Cyberattack. Show all posts
Showing posts with label Cyberattack. Show all posts

Saturday, June 11, 2011

Nobody is immune to cyberattack

Around the world, computer networks are getting more vulnerable even as they grow more sophisticated. They are being penetrated and looted by digital intruders.

The personal records of 100 million people were stolen in an attack on Sony Corp.’s video game networks. Up to 210,000 unemployed Massachusetts residents were put at risk by data theft software that infected computers at the state’s Executive Office of Labor and Workforce Development. And, in March,
as mentioned in an earlier post, criminals stole vital information from data protection company RSA Security, a division of storage giant EMC Corp. The stolen RSA data was later used in a hacker raid on defense contractor Lockheed Martin Corp., an RSA client. The list of data breaches grows almost daily, and while consumers and businesses can take steps to reduce the risk of losing sensitive information, security analysts say that making our computer networks truly secure is virtually impossible.

Antivirus and other commercial security software products may be adequate against the kind of amateur hackers who vandalized websites in the Internet’s early days, but they often fail to detect the custom-made attack programs, or “malware,’’ created by today’s organized crime gangs and foreign intelligence agencies. Cybercrime by governments will probably be even tougher to fend off. In late 2009, computers at the search engine giant Google Inc. came under a severe attack aimed at getting access to the company’s software codes. A host of other companies, including Adobe Systems Inc. and Juniper Networks Inc., were also hit. In January 2010, Google attributed the attack to hackers working from within China, a claim the Chinese government rejected.




The International Monetary Fund was hit recently by what computer experts describe as a large and sophisticated cyberattack whose dimensions are still unknown. The fund said that it did not believe that the intrusion into its systems was related to a sophisticated digital break-in at RSA Security that took place in March, which compromised some information that companies and governments use to control access to their most sensitive computer systems. After that attack, the World Bank briefly shut down external access to its most sensitive systems, for fear that the stolen information could make it a target. But it quickly resumed its normal operations and says it has seen no evidence of any attacks.

Companies and public institutions are often hesitant to describe publicly the nature or success of attacks on their computer systems, partly for fear of providing information that would be useful to the individuals or countries mounting the efforts. Even so, Google has recently been aggressive in announcing attacks and, in one recent case, as mentioned above, of declaring that its origin was China, an accusation the Chinese government quickly denied.


But in the case of the I.M.F., officials declined to say where they believe the attack originated — a delicate subject because most nations are members of the fund. The attacks were likely to have been made possible by a technique known as “spear phishing,” in which an individual is fooled into clicking on a malicious Web link or running a program that allows open access to the recipient’s network. It is also possible that the attack was less specific, a case in which an intruder was testing the system merely to see what was available.


Caveat emptor.

Wednesday, July 8, 2009

Cyberattacks Can Harm And Website Monitoring Can Benefit Electronic Health Records (EHR)

Cyberattacks have crippled the Web sites of several major American and South Korean government agencies since the July 4th holiday (U.S.) weekend.

The Washington Post , which also came under attack, reported on its Web site today that a total of 26 Web sites were targeted. In addition to sites run by government agencies, several commercial Web sites were also attacked, including those operated by Nasdaq, it reported, citing researchers involved in the investigation.

Authorities suspected that the hackers used a new variant of the denial-of-service (DoS) program to attack the Web sites. A denial-of-service attack is one in which an attack, sometimes from a single source, overwhelms a target computer with messages, denying access to legitimate users without actually having to compromise the targeted computer. Although frequently intentional, a DoS can also occur unintentionally through a misconfigured system.

In several of my prior posts, I discussed the [national and international] push toward a system of interconnected Electronic Health Records (EHR) networks. This system, like those cited in today's media reports, depends on the availability of well performing Web sites.

An Associated Press article in today's newspapers refers to Keynote Systems, a company that monitors such events, so I decided to look into their services. I had written on other aspects of this subject in the article Capacity and Disaster Recovery Planning for an Internet Connection to which I link in my bibliography at the very bottom of this blog.

Keynote Systems is a mobile and Web site monitoring company based in San Mateo, Calif. The company publishes data detailing outages on Web sites, including 40 government sites it watches.

Managing a single Web application with thousands of users typically requires a system administrator and a few support personnel, at a cost of up to $30,000 per month. About 20% of this cost, or about $6,000 per month or $72,000 per year, is spent on monitoring the reliability and availability of these services. Keynote Systems’ services to monitor URLs start at $100 per month or $1,200 per year -- the cost savings to an operations team can be significant.

Keynote Systems’ test and measurement products and services are driven by a global network of more than 2,600 measurement computers and mobile devices in more than 240 locations in 160 metropolitan areas around the world -- the largest on-demand test and measurement network in the world. Users know precisely how Web sites, content, applications, and services will perform on mobile networks and devices -- all with hard metrics that test precise behavior patterns and more accurately predict performance problems.

Test and measurement products and services deliver in-depth, relevant KPIs (a subject which I discuss in my article cited above) that are easily understood and accurately represent what happens in the real world -- using real browsers and real devices. The economic gains provided by using Keynote Systems’ network are upfront -- using Keynote Systems does not require an increase in capital expenses.

Their Web site offers a free evaluation of their software-as-a-service (SaaS) and downloadable software products. While I don't recommend that you immediately send them or any other like organization a check, I do think you should know about what they have to offer.