Risk Analysis

Most businesses and organizations have a web presence to share information on the Internet with interested parties. Consider the amount of data that can be obtained through an organizations web site, almost any information that has been used in the daily course of operations has likely moved through the web server. There are financial records as well as personally identifiable information pertaining to the customers. This amount of information becomes a high value target for would be attackers.

Stories in the news media of breaches to corporate data are not rare, quite the contrary most people hear about these data breaches regularly. Not only is a data breach a stain on the company’s image it can have serious consequences to the victims whose information was stolen. Identity theft can cause tremendous hardship, not only are there inconveniences such as changing credit cards but there too can long lasting effects from a damaged credit report. Web servers have become a prime target for attackers seeking valuable information.

Not only are attackers looking for financial or personal information alterations on an organizations web site are also common targets. Attackers that have philosophical or political differences with a company can target webservers to place embarrassing or misleading information. When unauthorized individuals alter a corporation’s web presence it can cause mistrust among its customers and business partners. Web site defacement is a common tactic employed during a web attack against an organization.

With the amount of data available on web servers and the public’s reliance on accessing this information via the Internet organizations need to take steps to mitigate the risks of attack. Web servers are a vulnerable target that carries a high reward with little risk. Some companies would rather hide the fact their server was breached than take the proper steps to mitigate risks. Not having a mitigation plan in place can expose the organization to unnecessary risks and potential liability in the event of an online attack.

The economic damages to an attack coupled with the damage to reputation can be catastrophic to a business. Consider the impact that a data breach had on Yahoo, between 2013-2014 approximately 1.5 billon user accounts were compromised (Armerding, 2018). The news was released in 2016 during sales negations, this revelation caused the price to fall by 350 million dollars (Armerding, 2018). Most organizations would be crippled or possibly bankrupted by an attack of this magnitude. The Yahoo attack targeted the real names, addresses, dates of birth, and telephone numbers, in some cases even the security questions and answers were compromised (Armerding, 2018).

Attackers are not just looking for personal information but also financial information. In 2008 Heartland Payment Systems exposed 134 million credit cards through a SQL injection attack (Armerding, 2018). The attack was not discovered for almost a year, when credit card issuers notified the company of suspicious transactions (Armerding, 2018). Heartland was found to not be compliant with the Payment Card Industry Data Security Standard and paid 145 million dollars in compensation because of the breach (Armerding, 2018).

biggest-data-breaches-by-year-and-accounts-compromised-1-100738435-large

Security must be a top priority for businesses. Consider the two examples above and the financial impact that a security breach can have on an organization. Most companies run on tight margins that cannot afford the unforeseen burden of losses in the millions of dollars, let alone the lasting impact of public perception due to a data breach. Organizations need to mitigate their risks as the sophistication of the attackers continues to grow. Not only are organizations needed to safeguard against small groups of attackers that work for personal gain but must protect against state sponsored groups with vast resources expert knowledge (Armerding, 2018).

Keeping a secure webserver is one of the foundations of a good security policy. The web server is the main point of online contact for visitors coming to an organizations website (Techopedia, n.d.). The web servers deliver data to browsers that request data, it is not uncommon for companies to have several different web servers to run their online presence (Techopedia, n.d.). With the numbers of servers that are running on the internet it is not a surprise that they are so commonly targeted for exploitation.

Over 45 percent of webservers run Apache server to perform the functions of a web server (W3Techs, n.d.). This provides many potential targets that perform in a similar manner. Web servers running open source software that have known bugs that are not patched can become an inviting target for would be attackers. For comparison only about, 10 percent of web servers run Microsoft IIS operating systems (W3Techs, n.d.). It is important for IT personnel to keep software up to date to minimize security risks.

Despite the financial devastation that can occur from a data breach some organizations are more concerned with the damage to their reputation after a security event (Security Magazine, 2017). The biggest fear that many companies express is not the data breach but potential long-term damage to their brand (Security Magazine, 2017). It is interesting that numerous corporations would be more concerned with their reputation than with the safety of their customer’s data, considering that nineteen people fall victim to identity theft every minute (Trans Union, 2016).

It is reported that 76 percent of organizations do not have a strategy or fundamental knowledge with regard to critical assets and vulnerabilities (Security Magazine, 2017). Despite the risks that their customers face for identity theft most organizations do not have a comprehensive security policy in place. Individuals who face personal data theft can have accounts opened in their name and suffer long term credit rating damage (Trans Union, 2016). Not only will the customer have to prove that the accounts were opened fraudulently but there could be significant court costs to deal with creditor lawsuits (Trans Union, 2016). With the potential damage that can occur to customers organizations would be well served from making security a priority for their customers as well as their bottom line.

There are numerous methods that attackers can use in an attempt to gain access to unauthorized information. According to Rapid 7, a computer security company some of the most common are:

  • SQL Injection Attack: This attack uses malicious code that is injected into a SQL statement that causes the server to display information that it normally would not show. This can be a serious concern if there is sensitive customer data stored on the server. This attack works by exploiting known SQL vulnerabilities.
  • Cross Site Scripting: This attack is similar to SQL injection but rather targets the user visiting the website. Malicious code is placed on the compromised site and then runs on the visitor’s browser, this attack targets the visitor and not the organization itself.
  • Denial of Service Attacks: This type of attack overloads the webserver of the organization with more traffic than it was designed to handle, thus rendering the website inoperable.
  • Session Hijacking and Man-in-the-Middle Attacks: This type of attack involves hijacking the session id between a legitimate user and a webserver and using it for unauthorized access. If the attacker gets between the user and the webserver this is known as a man in the middle attack and the attacker can read information in both directions.

With these types of risks and the potential financial devastation that can occur with a data breach web server security needs to be on the top of any organizations list.

Implementation of an IT governance framework can help organizations mitigate risks as well as improve their bottom line, thereby satisfying the need for customer security and maintaining brand image. Agencies with effective IT governance generate more return on their IT investments than their competitors (Devos & Van de Ginste, 2015). Implementation of COBIT framework tackles the following needs:

  1. Meeting Stakeholder Needs
  2. Covering the Enterprise End to End
  3. Applying a single, Integrated Framework
  4. Enabling a Holistic Approach
  5. Separating Governance from Management (Devos & Van de Ginste, 2015).

Through the use of a framework security needs for the organization as well as the customer can be maintained, and risks mitigated.

 

 

 

 

 

References

Armerding, T. (2018, Jan. 26). The 17 biggest data breaches of the 21st century. Retrieved from CSO Online: https://www.csoonline.com/article/2130877/data-breach/the-biggest-data-breaches-of-the-21st-century.html

Devos, J., & Van de Ginste, K. (2015). Towards a Theoretical Foundation of IT Governance – The COBIT 5 Case. The Electronic Journal Information Systems Evaluation, 95-103.

Rapid 7. (n.d.). Common Types of Cybersecurity Attacks. Retrieved Aug 17, 2018, from Rapid 7: https://www.rapid7.com/fundamentals/types-of-attacks/

Security Magazine. (2017, Feb 3). Enterprises Fear Brand Damage More Than Breaches. Retrieved from Security Magazine: https://www.securitymagazine.com/articles/87779-enterprises-fear-brand-damage-more-than-breaches

Techopedia. (n.d.). Web Server. Retrieved Aug 17, 2018, from Techopedia: https://www.techopedia.com/definition/4928/web-server

Trans Union. (2016, Oct 12). What are the Effects of Identity Theft? Retrieved from Trans Union: https://www.transunion.com/blog/identity-protection/what-are-the-effects-of-identity-theft

W3Techs. (n.d.). Usage of Webservers for Websites. Retrieved Aug 18, 2018, from w3Techs: https://w3techs.com/technologies/overview/web_server/all

 

Email Tech

Server and Client in email Communication

Email is something many of us use and don’t think much about. There is quite a bit of information shared in the process of sending an email. Consider that we can send an email from almost any place on Earth to almost any other place, including space. The ability to send communications quickly and easily has caused email communication to be immensely popular.

server_close-up

An email client is the software that a user creates an email message with, such as gmail (whatismyipaddress.com, n.d.). Once the user hits send the email message goes to an email server (whatismyipaddress.com, n.d.). The email servers know how to route the message based on the email address, the address is translated to an IP address through a DNS server (whatismyipaddress.com, n.d.). The process of sending and receiving emails involves a few different servers and networks depending on the origination and destination of the message.

Email Phishing

Based on the popularity of email communication it is no wonder that bad actors have used email for criminal pursuits. One scam that is prevalent in email is called phishing. Phishing attempts to get personal information from the victim (Sankhwar & Pandey, 2017). In a typical phishing attempt a scammer will send an email that looks like it is from a bank, credit card, or other utility (Bernard, 2018).

Phishing originally worked by flooding email address and hoping that based on the number of emails sent a few victims would reply. In this method a generic email would be sent to thousands of individuals, the contents of which asked usually asked for help with a foreign transaction. In this type of phishing scammers would relied on unsuspecting email users and hoped that perhaps one in a thousand would reply (Bernard, 2018).

As the numbers of email users have grown over the years so too has the sophistication of the email scams (Sankhwar & Pandey, 2017). Now scammers will target individuals, the scams are directed and targeted with an appearance of authenticity (Bernard, 2018). As noted by Bernard (2018), there is little risk and the possibility of high reward in these situations, so it is unlikely these activities will be stopping anytime soon.

 

Some Examples of criminal activity supported through email include:

1.Ransomware
Ransomware infects your computer and encrypts your files until the user pays the ransom.

2.ID Theft
Scammers will open credit accounts in the victim’s name by applying for credit with stolen information.

3.Unauthorized Access

Unauthorized access to computer systems by phishing for information.

4.Control of Machine

Putting software on a machine sent through email that will allow a scammer to control a victim’s machine for their own purposes.

 

Email Spoofing

One of the more common ways for victims to fall to email scams is through spoofing. Email spoofing makes it look like an email message came from an address that it did not actually come from (Iyer, Atrey, Varshney, & Misra, 2017). Employing spoofing a scammer sill forge the email source so that it appears that the email came from a legitimate address, such as the victim’s bank (Iyer, Atrey, Varshney, & Misra, 2017). The information in the email header is different in a spoofed email than one originating from a legitimate source (Iyer, Atrey, Varshney, & Misra, 2017).

 

 

 

Email Headers

Below is an example of headers that can be found in a Google email message.

email header example

Laws Against Phishing and Computer Abuse

In the United States there are laws against using computer systems for criminal activities. In the state of California there is the Anti-Phishing Act of 2005 that forbids the use of email messages, web pages, and other electronic means to solicit identifying information fraudulently (State of California, 2006). Federally there is the Computer Fraud and Abuse Act which prohibits accessing computer systems without authorization (Cornell Law School, n.d.). Despite these laws the advancement of technology is too quick for the criminal justice system to keep up. Prosecutions for phishing related crimes are rare.

 

Simple Steps to Protect Yourself

There are some common giveaways that can alert you to a potential phishing email. The list below outlines the common red flags that should be avoided to keep your online activities safe. The following list from Bernard (2018),  is not all inclusive but does cover the most common scenarios.

An unusually large amount of spelling and grammar errors

Generic web email address

Inaccurate and unusual jargon

Links that don’t go to the correct address

Asking for help with foreign financial transactions or sales

 

References

Bernard, N. (2018). Reasonably Suspicious: Avoiding Targeted Email Scams. Utah Bar Journal, 37-41.

Cornell Law School. (n.d.). 18 U.S. Code § 1030 – Fraud and related activity in connection with computers. Retrieved from Legal Information Institute: https://www.law.cornell.edu/uscode/text/18/1030

Iyer, R. P., Atrey, P. K., Varshney, G., & Misra, M. (2017). Email Spoofing Detection Using Volatile Memory Forensics. 2017 IEEE Conference on Communications and Network Security, 619-625.

Sankhwar, S., & Pandey, D. (2017). A Comparative Analysis of Anti-Phishing Mechanisms: Email Phishing. International Journal of Advanced Research in Computer Science, 567-574.

State of California. (2006, Jan 1). Business and Professions Code. Retrieved from California Legislative Information: http://leginfo.legislature.ca.gov/faces/codes_displayText.xhtml?lawCode=BPC&division=8.&title=&part=&chapter=33.&article

whatismyipaddress.com. (n.d.). What is a mail server. Retrieved July 31, 2018, from what is my ip address: https://whatismyipaddress.com/mail-server