Posts Tagged ‘Hacking’

Software to fight hacking technique bags award

October 31st, 2010

One of the serious threats to a user’s computer is a software program that might cause unwanted keystroke sequences to occur in order to hack someone’s identity.

This form of an attack is increasing, infecting enterprise and personal computers, and caused by “organized malicious botnets,” said Daphne Yao, assistant professor of computer science at Virginia Tech.

To combat the “spoofing attacks,” Yao and her former student, Deian Stefan, now a graduate student in the computer science department at Stanford University, developed an authentication framework called “Telling Human and Bot Apart” (TUBA), a remote biometrics system based on keystroke-dynamics information.

Their work won a best paper award at CollaborateCom ‘10, the 6th International Conference on Collaborative Computing, held in Chicago and sponsored by the Institute of Electrical and Electronic Engineers’ Computer Society, Create-Net, and the Institute for Computer Sciences.

Yao holds a patent on her human-behavior driven malware detection technology, including this keystroke anti-spoofing technique. Her technology for PC security is currently being transferred to a company. The license agreement between the company, Rutgers University (Yao’s former institution), and Virginia Tech is expected to be finalized in the coming weeks.

Internet bots are often described as web robots. They act as software applications that run automated tasks over the Internet. Bots usually perform simple and repetitive tasks, but at a much higher rate than would be possible for a human alone. When used for malicious purposes they are described as malware.

“Keystroke dynamics is an inexpensive biometric mechanism that has been proven accurate in distinguishing individuals,” Yao explained, and most researchers working with keystroke dynamics have focused previously on an attacker being a person.

The uniqueness of Yao and Stefan’s research is they studied how to identify when a computer program designed by a hacker was producing keystroke sequences “in order to spoof others,” they said. Then they created TUBA to monitor a user’s typing patterns.

Using TUBA, Yao and Stefan tested the keystroke dynamics of 20 individuals, and used the results as a way to authenticate who might be using a computer.

“Our work shows that keystroke dynamics is robust against the synthetic forgery attacks studied, where the attacker draws statistical samples from a pool of available keystroke datasets other than the target.

Source:http://news.oneindia.in/2010/10/31/softwareto-fight-hacking-technique-bags-award.html

Computer hacking

September 19th, 2010

Internet hackers and software companies from around the world are staging mock cyber wars at a major web security event in Europe.

Some 1,000 participants are taking part in the two-day Hacktivity 2010 conference in the Hungarian capital Budapest that started on Saturday. The conference comes at a time of mounting concern over software piracy and other cyber crimes. Hacking is fast becoming the 21st century tool for espionage.

Software companies these days use hackers to see how secure their new programs are – hackers benefit by learning new tricks.

“There are not many systems these days that cannot be hacked. It is a matter of time and investment,” Felix F-X Linder, a cyber security specialist, told Al Jazeera from the conference in Budapest. “Luckily, due to the many years of work in computer security, it is getting harder to hack systems.”

Mitch Altman, a hacker from the US, will present a workshop on computer hardware, while Bruce Scheier, a world-renowned cyber security expert, opened the conference with a keynote speech.

At the leisure zone, where “nerds” at the conference go to relax, participants can test their ability to break into systems and take control of foreign computers in a variety of games, from Hack the Vendor to Capture the Flag.

According to a recent study by the cyber security firm Norton, 65 per cent of all computers users have been the victims of cyber crime. The worst hit country is China, where 83 per cent of users have been hit by some form of cyber crime. In Brazil and India that number is 76 per cent.

Cruel intentions

Malicious computer use such as virus writing and hacking cost businesses globally more than $1 trillion each year, according to a study from computer security company McAfee. The projection is based on responses to a survey of more than 800 chief information officers of companies around the world.

The respondents estimated that in 2008 they lost data worth a total of $4.6bn and spent about $600 million cleaning up after breaches, McAfee said.

The recent recession is only increasing the security risk for corporations, respondents said, with 42 per cent reporting that displaced workers were the biggest threat to sensitive information on the network.

More than one quarter of the respondents said they avoid storing data in China, and 47 per cent of Chinese respondents said they believed the US poses the biggest security threat to their data.

The research also indicates that more and more vital digital information, such as intellectual property and sensitive customer data, is being transferred between companies and continents – and lost. The average company has $12 million worth of sensitive information residing abroad. Companies lost on average $4.6 million worth of intellectual property each year.

Taliban hacked

Business, government and regular computer users are not the only ones dealing with hackers: the Taliban is also facing the problem. The so-called Islamic Emirate of Afghanistan faced an attack in June 2010, Wired magazinereported.

Abu al-Aina’a al-Khorasani, an administrator with what Wired calls an “elite jihadi forum endorsed by the Taliban”, has cautioned users to be careful of recent activity.

Khorasani said that the “group’s main site and the site of its online journal Al-Sumud, have been subject of an ‘infiltration operation’”.

On the Falluja forum, Khorasani warns online Islamists “to not enter any of the links of these website and not to even surf [the material] until you receive the confirmed news by your brothers, Allah-willing”, Wired reported.

The Taliban websites have been hacked before, but the latest job should be particularly concerning to the group, Evan Kohlmann, a computer analyst with Flashpoint Partners, said.

“[T]his would be the first instance that I’m aware of it being actually ‘infiltrated’,” Kohlmann told Wired.

“It’s an unsettling prospect for security-minded online jihadists, because such sites can be manipulated by a variety of hostile parties in order to harvest a breathtaking amount of personal data on regular visitors.”

Victims ignorant

Generally people do not take cyber threats very seriously and most people who have been hacked do not even know it. They forget that by using unsecured Wi-Fi hotspots they are essentially shouting their information to the world.

Every access point into a system like Bluetooth or other communication software can be used by savvy cyber criminals to steal information or to implant malicious software. The average laptop could contain data worth around $1 million, according to research by security software company Symantec.

The same research shows that just 42 per cent of companies automatically back up employees’ emails, where often critical data is stored, and 45 per cent leave it to the individual to do so.

Lost laptops have been the bane of existence of many companies and countries alike. The most infamous instance of loss of laptop occurred in 1990 when a British Royal Air Force officer had a computer stolen from the boot of his car. It contained a top secret plan to drive the Iraqi army out of Kuwait after it had invaded the Gulf country in August 1990.

In January 2008 a British Royal Navy officers was court-martialled after a laptop containing the personal data of 600,000 people, including serving personel, was stolen from his car. The non-encrypted date included bank account numbers and passport details, national insurance numbers and home addresses.

Most laptop thefts are committed by common thieves who are after the laptop itself and not the information it contains. To prevent the thief to access the system it is enough to simply set the password and encrypt the hard drive.

Source:http://english.aljazeera.net/news/europe/2010/09/201091994759505477.html

Hacking is easy, says security specialist

August 23rd, 2010

A computer hacker compromised Hell’s Pizza’s database and stole a history of customers’ pizza orders simply because he could, according to a crusader against computer hacking.

Mike Prow, managing director of Aura Software, showed the Waikato branch of the NZ Computer Society at Wintec last week how a badly built website could be hacked by typing a few simple commands into its search engine.

“Does this happen in New Zealand? Two-hundred-and-thiry-thousand customer records were stolen from Hell’s Pizza.”

Details of Green Party MP Nandor Tanczos, who lives near Huntly, were stolen alongside their passwords, email and home addresses and phone numbers. Other prominent Hell’s Pizza customers were DJ Mike Puru, Target presenter Brooke Howard-Smith, comedian Dai Henwood and entrepreneur Seeby Woodhouse.

“They were hacked because they could be. New Zealand is not off the radar,” Mr Prow said. He demonstrated how someone with the programming knowledge of a first year or second year IT student could access a business or government department database by typing a few commands.

Mr Prow showed how easy it was to access data linked to people who had logged on to the site, and how to embed his own commands which made messages pop up to third-party viewers going to the site and infect them with malware – malicious software – which could cause damage to their own computer systems if not detected.

“It’s very much `user beware’,” Mr Prow said.

Mr Prow, whose business offers “white hat hacking” to clients to assess how vulnerable their systems are, gave the demonstration at the Hamilton city campus of Wintec during a New Zealand Computer Society event to warn website builders to take every possible security precaution.

“It’s all about raising security awareness,” said Mr Prow, whose talk was entitled “Teaching the Good Guys Bad Tricks”.

Source:http://www.stuff.co.nz/waikato-times/business/4050850/Hacking-is-easy-says-security-specialist

Get Adobe Flash playerPlugin by wpburn.com wordpress themes