Dr Eugene Shultz looks at the practice of computer forensics during a real-life incident.
The publisher regrets that this article is an accidental duplication of an article that has already been published, doi:10.1016/j.cose.2007.05.001. The duplicate article has therefore been withdrawn.
The areas of physical security and information technology (IT) are often if not usually worlds apart. The same is true for physical security and IT security; in most organizations separate functions for physical security and IT security exist. Because these functions are in place and because they at least in part achieve their goals, management tends to perceive that major risks they try to mitigate are being addressed. Convergent security risks in physical security systems and information technology (IT) are, however, almost without exception overlooked. Physical security systems and devices, process control systems, and IT infrastructures are being integrated without sufficient consideration of the security risks that the increasing intermingling of these systems and infrastructures introduces. Serious security-related incidents due to unmitigated physical convergence risks are starting to occur. Adequately dealing with the convergence problem requires organizations to implement multiple solutions.
Dr Gene Schultz reviews what academic progress has been made in the security usability research area. Dr Schultz finds there is an acute shortage of research on the subject. Dr Eugene Schultz examines a number of research papers on information security usability.
The future of intrusion prevention is likely to be marked by significant technical advances, but currently it is still strongly supported by its technological predecessor. Despite predictions by IT analyst Gartner – in 2003 – that Intrusion Detection Systems (IDS) would be history by now – replaced by Intrusion Protection Systems (IPS), the former is still going strong. Dr Gene Shultz says that security professionals are increasingly seeing IDS and IPS as two overlapping but different technologies and IDS sales have continued to grow. Nevertheless IPS continues to grow popular. This issue of Computer Fraud & Security looks at four predictions for the technology's future. Dr Gene Schultz believes the improvements of IDS, which provides the foundations for IPS, will buoy the latter along. He says zero day attacks that systems may have failed to detect seven years ago are now being found. Also, IPSs are set to play a larger role in forensics data preservation by providing data to a forensics server while preserving the integrity of the data. "More advanced response capabilities will allow users and organizations to choose from a wide range of response mechanisms as well as fine tune them to more closely meet their business and operational needs," says Schultz. The big four predictions:Prediction 1: Better underlying intrusion detectionPrediction 2: Advancements in application-level analysisPrediction 3: More sophisticated response capabilitiesPrediction 4: Integration of intrusion prevention into other security devices The big four predictions: Prediction 1: Better underlying intrusion detection Prediction 2: Advancements in application-level analysis Prediction 3: More sophisticated response capabilities Prediction 4: Integration of intrusion prevention into other security devices Intrusion prevention has gained in popularity to the point where it is now widely considered a mainstream security technology. Intrusion prevention is similar to intrusion detection in that it is designed to identify potential and actual security breaches in near-real time, but intrusion prevention goes farther than intrusion detection in that it provides the ability to respond defensively to attacks, thereby preventing them from succeeding – at least in the ideal case. Because so many attacks occur so swiftly, automated mechanisms designed to thwart them may not be able to stop them from initially succeeding, however. In such cases, intrusion prevention mechanisms often attempt to prevent the attack from spreading any farther.
Windows Vista will be released in early 2007 heavy with the promises that come with a new start, mostly concerning security. Some of the promises take Microsoft's new OS significantly further than previous versions. It has even been suggested by a senior MS employee that antivirus will no longer be needed for the new OS. In particular, troubled IE 7 will get a makeover exclusive to Vista. The browser can run in protected mode, has ActiveX Opt-in, a phishing filter and protection against cross-site scripting. Vista will come with many new security features – not all of which are plain sailing. The User Account Control feature means a user cannot install software unless they have Administrator privileges. But running in Administrator mode can make compromise much easier. Vista also has a new program called Windows Defender, which uses signature updates to help protect against pop-up ads and spyware. A new default firewall in the OS monitors inbound and outbound traffic to stop infected PCs making connections. Vista also has a mechanism to try and prevent data seepage through removable devices where an administrator can disallow any kind of storage device. Edward Ray and E Eugene Schultz evaluate the likely fruitful return of Microsoft's endeavours. Vista's features: User Account Control (UAC) Windows Defender Windows Firewall Internet Explorer 7 (IE7) Protected mode ActiveX Opt-in Cross-site scripting protection Phishing filter Encrypting File System (EFS) Device Control BitLocker Drive Encryption Rights Management Services Edward Ray and E Eugene Schultz scrutinise whether Microsoft's upcoming new OS will fulfill its security promises.
Personal information and organizational information need to be protected, which requires that only authorized users gain access to the information. The most commonly used method for authenticating users who attempt to access such information is through the use of username–password combinations. However, this is a weak method of authentication because users tend to generate passwords that are easy to remember but also easy to crack. Proactive password checking, for which passwords must satisfy certain criteria, is one method for improving the security of user-generated passwords. The present study evaluated the time and number of attempts needed to generate unique passwords satisfying different restrictions for multiple accounts, as well as the login time and accuracy for recalling those passwords. Imposing password restrictions alone did not necessarily lead to more secure passwords. However, the use of a technique for which the first letter of each word of a sentence was used coupled with a requirement to insert a special character and digit yielded more secure passwords that were more memorable.
They are still A- bot There are less destructive viruses around – there is no doubt about it. Where are the Blasters and Slammers? Dr Gene Schultz believes that they have been reborn as bots. Malware writers are shifting their focus from unleashing massive, destructive viruses to harvesting thousands of bots. Botnets are stealth and sneaky, trying to avoid detection – while old school viruses like Blaster were loud and ubiquitous. Bots work quietly while the viruses of old wreaked unmissable havoc across thousands of computers internationally. And some anti-virus tools are sometimes useless in recognising botnets. Botnets are much more widespread than people know – the stealth way in which they operate makes them hard to detect. The switch from viruses and worms is likely due to the variety of ways that bots can make money for zombie masters. Botnets can be sold, used to send spam, for Dos attacks and extortion. Schultz also explores other reasons for why there are less mass worms as follows: • More companies use anti-virus software. • There are fewer vulnerabilities for viruses to exploit. • Boredom has demotivated virus and worm writers. • Worm and virus writers are scared of the repercussions. • Worms and viruses target more niche systems were mass spreading is impossible. There is a new trend in malware and organizations have to adapt to fight it. Although many new worms and viruses surface every week, they are becoming less widespread than those in previous years. In contrast, bots and botnets are becoming more prolific and troublesome; botnets consisting of hundreds of thousands of bots or even more are not uncommon. Bot writers and botnet operators have numerous motives for engaging in their sordid activity, but the desire to make money has become by far the chief motivator. Meanwhile, the nature of current worms and viruses is also changing considerably—a growing number of them uses instant messaging (IM) to replicate, and worms and viruses that target handheld computing devices are also becoming more prevalent. Bots and botnets pose very elevated levels of risk, risk that needs to be controlled through a variety of security countermeasures.