Tuesday | 7 October, 2008
CIO
Security researchers begin on active defences
It will only be a matter of time before there are tools readily available to automate the process of 'reverse-hacking'.
Carl Jongsma (Computerworld) 15 April, 2008 20:51:43

Many people fear them, but most hackers are no more than simple point and click operators (the basic script kiddie) that are incapable of anything but using tools created by others.

Like any other software developer, those who do create the tools being used by the script kiddies are not immune to coding errors and poor development practices. In a presentation at RSA 2008 by BitSec researcher Joel Eriksson, demonstrated a practical example where a 'white hat' hacker was able to utilise weaknesses in a 'black hat' tool in order to counter-hack the attacker's system. Even with updates to the hacker's tool, there were significant weaknesses that remained which allowed Eriksson to continue to access the systems of those who were using the tool actively.

This concept is one that is beginning to gain traction amongst researchers, with a number of Web security experts looking at different methods to identify and potentially attack the system that is launching an attack against a site or local system.

As the techniques in use are not overly complex (they are a lateral application of existing, logical functionality), it will only be a matter of time before there are tools readily available to automate the process of 'reverse-hacking'.

Introducing the ability to identify the source system, even through a network of proxies and local networks, when the attack is underway, is an opportunity that will be extremely valuable for later reconstruction, forensic analysis, and possible prosecution -- once the tools are designed and built.

While the techniques that are being discussed at the moment are focussing on the enumeration and discovery of where and what is launching an attack, it doesn't take much to theorise an active defensive system that neutralises the attack platform.

Although this process is bound to be fraught with legal uncertainty and danger, it poses an ethical problem for the white hat -- do they take the opportunity to neutralise the problem when it is first identified, given that they are now reaching beyond their network perimeter and directly affecting another system (bound to be illegal in most jurisdictions), or do they ignore the capability that they have recently developed, and the attacker continues on without fear of reciprocation?

Even if most researchers do not implement the capability to attack, there will be those who do write tools with such capability and they will be readily available for those who want them.

The techniques being described at the moment are dependent on the attacker's system providing the default responses to queries being made of it. With increased knowledge that reverse probing and attack is possible, the arms race will continue and there will be greater use of response customisation by skilled attackers to redirect attention to innocent systems.

As with most crime, the skilled and careful attacker will continue to evade detection and capture. What is now being looked at is another set of tools to identify and capture the lesser skilled.

More about Web Security, RSA, Logical
Market Place
 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
  • +

    CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00

    Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00

    Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05

    Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    Corporate security and the climate crisis 03 October, 2008 11:21:00

    How to adapt security and risk management policies - including IT security - to deal with climate change.
    US military strategists, CIA analysts, international agency officials and Nobel Prize winning economists concur with the consensus of the world's scientific community: the Climate Crisis is a planetary security issue, as well as a national security issue for each of the one hundred ninety two countries that belong to the United Nations. But the Climate Crisis is also, by extension, a corporate security issue, as well as, yes, a cyber security issue.
  • +

    Companies own up to virtual security blind spot 02 October, 2008 11:05:00

    VMWorld attendees reveal vast majority of companies have little or no security in place for their virtual systems.
    The vast majority of companies have little or no security in place for their virtual systems. That is a scary statistic revealed in a survey of attendees at the recent VMWorld 2008 conference in Las Vegas.
  • +

    How to minimize the impact of a data breach 01 October, 2008 08:54:00

    ID Experts' Rick Kam describes a customer-centric action plan
    Thirty-one percent of customers--nearly one-third of a company's client base and revenue source--are terminating their relationship with organizations following a data breach, according to a recent study by the Ponemon Institute.
  • +

    Five mistakes security pros would make again 30 September, 2008 10:18:00

    Whether it's getting fired for standing up for what's right or making a network configuration mistake that leads to better security, there are some mistakes worth making. Five security pros offer personal examples.
    Ten years ago, Michael Riva was network administrator for a top-five American consultancy. Employees were downloading graphic pictures and videos onto the network. Riva told his boss a proxy server with content filtering might be in order; his boss laughed and suggested they put in a bigger file server instead.
  • +

    What does the financial meltdown mean for security? 29 September, 2008 10:25:00

    Bill Brenner wonders if it's irrational or appropriate to make connections between the current financial crisis and the state of security
    At first, this was going to be a column about the PR machine's hyperbolic efforts to connect the state of IT and security with the current financial crisis. Indeed, some have shamelessly sent me story pitches that try to get some bang out of the Wall Street meltdown.
CIO Webcast Innovation #8 - What are the biggest roadblocks to IT's involvement in innovation at your company?
Watch the latest latest edition of CIO Innovation which is now available for download.
Watch the webcast
Sign up to the CIO Innovation update email


CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II
Listen to the latest edition of CIO Live which is now available for download.
Listen to the podcast
Sign up to the CIO Live email
Whitepaper

Best Practice in Building an Integrated Information Management Strategy

Discover the business value that creating an integrated information platform can bring. Learn how to provide consistent, accurate information to all stakeholders within your business network. Integrate vital data from disparate sources and deliver a trusted information foundation. Read on to uncover the stepping-stones to your new information management strategy.

Sponsored Links