Meeting the PCI DSS Compliance Guidelines

Cloud computing has the ability to offer organizations long-term IT savings, reductions in infrastructural costs and pay-for-service models. By moving IT services to the cloud, organizations are more geographically distributed than ever before and the pace of business gets faster every day. Online collaboration has become a business necessity—there is no other way for distributed teams to work as quickly and efficiently as business demands. With virtual, paperless environments becoming more common, simply locking the doors at night no longer protects merchants, banks, customers or the business they conduct.

This means that exploitation will change from systems to web. Due to these changes, today’s business needs demand that applications and data not only move across physical and international borders, but also to the cloud and accessible by third parties. This loss of control is significant for security teams that must not only keep data safe, but also comply with the necessary security standards, including the Payment Card Industry Data Security Standard (PCI DSS). The payment card industry (PCI) should recognize that the most effective way to protect customer data is to protect the networks from the point of purchase to the application servers in their networks.

The PCI DSS security requirements apply to all system components included in or connected to the cardholder data environment. The cardholder data environment (CDE) is comprised of people, processes and technologies that store, process or transmit cardholder data or sensitive authentication data. “System components” include network devices, servers, computing devices and applications.

Compliance Challenges
Five compliance challenges organizations may encounter are:

  1. The cloud is relatively new technology and may be misunderstood.
  2. Clients may have limited visibility into the service provider’s infrastructure and the related security controls.
  3. It can be challenging to verify who has access to cardholder data process, transmitted, or stored in the cloud environment.
  4. Public cloud environments are usually designed to allow access from anywhere on the Internet.
  5. Some virtual components do not have the same level of access control, logging, and monitoring as their physical counterparts.

Meeting the Compliance Requirements
Shared hosting providers must protect each customer’s hosted environment and cardholder data. From 30 June 2015, these providers must meet specific, additional requirements that are set out in an appendix A of PCI DSS Version 3. Below are a few highlights:

  • PCI DSS requires that hosting providers ensure that each customer only runs processes that have access to that entity’s cardholder data environment.
  • Access and privileges must be restricted to each customer’s own cardholder data environment.
  • If a customer (merchant or service provider) is allowed to run its own applications on a shared server, it should run with the user ID of the customer, rather than as a privileged user.
  • Logging and audit trails must also be enabled, unique to each entity’s cardholder data environment and consistent with PCI DSS requirements.
  • Logs should be available to each customer, specific to their cardholder data environment.
  • Processes must also be available to provide timely forensic investigation in the event of any compromise of cardholder data or systems.
  • Even though a hosting provider meets PCI DSS requirements, the compliance of the customer using the service is not guaranteed.
  • Each entity will need to comply with PCI DSS and validate its own compliance as applicable.

PCI DSS compliance is mandatory for banks, merchants and providers that process, transmit or store cardholder data. The risk of noncompliance is substantial, including fines, potential security breaches and loss of business.

Any enterprise that falls with the scope of the standard must implement it and seek compliance. Merchants who fail to comply might be forced to pay an extra percentage for noncompliance. There are also fines for storing sensitive authentication data, which is not allowed under the standard. Penalties for data breaches in noncompliant companies can be severe, including large fines as well as the threat of future exclusion from the payment card network.

Adesanya Ahmed, CRISC, CGEIT, ACPA, ACMA
IT Security and Connectivity Consultant, Petrovice Resources International Ltd.
owos2001@yahoo.co.uk

[ISACA]

2014 Gartner Magic Quadrant for Integrated Systems

The integrated system market is growing at 50% or more per year, creating an unusual mix of major vendors and startups to consider. This new Magic Quadrant will aid vendor selection in this dynamic sector.

Market Definition/Description

This document was revised on 27 June 2014. The document you are viewing is the corrected version. For more information, see the Corrections page on gartner.com.

Integrated systems are combinations of server, storage and network infrastructure, sold with management software that facilitates the provisioning and management of the combined unit. The market for integrated systems can be subdivided into broad categories, some of which overlap. Gartner categorizes these classes of integrated systems (among others):

  • Integrated stack systems (ISS) — Server, storage and network hardware integrated with application software to provide appliance or appliancelike functionality. Examples include Oracle Exadata Database Machine, IBM PureApplication System and Teradata.
  • Integrated infrastructure systems (IIS) — Server, storage and network hardware integrated to provide shared compute infrastructure. Examples include VCE Vblock, HP ConvergedSystem and IBM PureFlex System.
  • Integrated reference architectures — Products in which a predefined, presized set of components are designated as options for an integrated system whereby the user and/or channel can make configuration choices between the predefined options. These may be based on an IIS or ISS (with additional software, or services to facilitate easier deployment). Other forms of reference architecture, such as EMC VSPEX, allow vendors to group separate server, storage and network elements from a menu of eligible options to create an integrated system experience. Most reference architectures are, therefore, based on a partnership between hardware and software vendors, or between multiple hardware vendors. However, reference architectures that support a variety of hardware ingredients are more difficult to assess versus packaged integrated systems, which is why they are not evaluated by this research.
  • Fabric-based computing (FBC) — A form of integrated system in which the overall platform is aggregated from separate (or disaggregated) building-block modules connected over a fabric or switched backplane. Unlike the majority of IIS and ISS solutions, which group and package existing technology elements in a fabric-enabled environment, the technology ingredients of an FBC solution will be designed solely around the fabric implementation model. So all FBCs are an example of either an IIS or an ISS; but most IIS and ISS solutions available today would not yet be eligible to be counted as an FBC. Examples include SimpliVity, Nutanix and HP Moonshot System.

Added market complexity is created because integrated systems of different categories are frequently evaluated against each other in deal situations. For instance, because IIS solutions are generic multipurpose systems that can run a variety of workloads, it is common for one IIS to be compared with another. But users who want to deploy a specific workload might compare an ISS solution, like Oracle Exadata Database Machine or IBM PureApplication System (both of which have the workload embedded), with a generic IIS system that is also capable of running the workload, or with an IIS platform that has an applicable reference architecture. However, it would be rare to see one ISS competing with another ISS, because the choice of stacks and workload takes priority over the choice of platform. So if Oracle Database Management System (DBMS) serving is the required workload, the only viable ISS solution would be an Oracle Engineered System.

It is because these different types of systems are evaluated against each other that this Magic Quadrant assesses integrated systems as integrated infrastructure systems or the infrastructure aspects of integrated stack systems. It assesses the hardware (server, network, storage), operating system and virtualization software alongside any associated management tools and high-availability (HA) solutions. It considers hardware depth and scale, software stack management breadth and depth, and support of the infrastructure, as well as flexibility in the use of reference architectures. It does not assess any software stack, application or platform components individually, such as middleware, DBMS software and cluster software in the application or DBMS tiers.

Most integrated systems are based on blade server technology, with closely coupled storage area network (SAN) and network-attached storage (NAS), which enable boot-from-disk capability for all physical and virtual nodes; thus, the system becomes stateless. Blades are not a prerequisite, however, and some vendors will promote rack-based solutions as well. The majority of integrated systems are the effective packaging of server, storage and networking components that are sold as separate products in their own right. But we are seeing the emergence of true “fabric-based computers” that merge the three elements more seamlessly.

The great majority of integrated systems are based on Intel or AMD x86 technology, but there is some support for reduced instruction set computer (RISC) variants like Power and SPARC, and the emerging market for ARM and Intel Atom processors will have applicability for some integrated system use cases.

View Report

Knowledge Is Power: Using Cyber Scrutiny To Defend Against Phishing Attacks

If you purchased an iPhone 6 recently, you probably received this email:

Some of you may have even clicked the “Verify Now” link and entered your Apple ID account information. I hope not, though, because this email is not from Apple. It’s a phishing email meant to trick recipients into giving sensitive information to the attacker who sent it.

This email illustrates two things:

  1. Attacks are more sophisticated as cybercriminals get smarter and craftier.
  2. An increased level of understanding regarding cyber attacks is needed, not just within the corporate community, but within the general public as well.

The market for enterprise network and cybersecurity grows each year highlighting the emphasis companies are putting on preventing modern threats from infiltrating their internal networks. However, the impetus is focused on technological preventative measures. Could an education in cybersecurity — who the attackers are, what they’re after, and the appropriate level of scrutiny that should be practiced — significantly bolster an enterprise’s cyber defense?

Yes. In 2011, RSA was the target of a spear phishing attack made successful by at least one employee opening the malicious attachment even after their spam filter had correctly placed the email in the “junk” folder. RSA suffered a data breach as a result.

“At least RSA’s SPAM filters were working, even if their social engineering training for employees was not,” -Avivah Litan, Gartner Analyst

More recently, a spear phishing attack targeting physicians at a Tacoma-based medical groupled to the breach of 12,000 patient records. Emails were crafted to appear as though they were sent from the group’s parent company, and prompted targets to click on a link and enter their email account username and password. The group has since rolled out a company-wide phishing prevention system, including retraining the employees who fell for the initial phishing email.

Spear phishing attacks are:

Lucrative. The black market for data is huge, estimated at multiple billions of dollars, meaning that the person or organization behind the attack may not actually use what they steal to make money. Unfortunately, this also means they’re more difficult for authorities to track down.

Successful. Because hackers take pains to get their targets to fall for their schemes, they know what company and department you work for, what applications you use, who you report to, and what kinds of projects you’re likely working on. They know which job titles are likely uninformed or unwary of potential threats. This makes spear phishing campaigns one of the most highly-favored APT attack methods.

Simply a means of getting in. Once a target is duped into clicking a link, opening a file, etc., the attacker can carry out his mission, whether it’s stealing personal information, using a target’s personal account to transfer money, extract intellectual property or insider information.

A real threat to both corporate and consumer spheres. Both have data that attackers want to use to make money, and most people who work for targeted companies have a home computer or mobile device for personal use that is not protected by enterprise network or endpoint security policies.

Recognizable… sometimes, if you know what you’re looking for.

  • Check the sender’s email address to make sure it’s someone from whom you should be receiving emails. If you’re still not sure, email clients like Outlook and web mail applications like Gmail usually have options to view email messages with the headers included, so you can make sure the “From” field matches the “Reply-to” field.
  • Look for patterns of misspellings and incorrect grammar.
  • Ask yourself if links and attachments within the message are expected information from the sender and work-related. Do the domain name or file name make sense? View the email with formatting turned off to view a link’s actual URL.
  • Check the attachment’s file extension. Odds are that unless you’re in the IT or engineering department, you shouldn’t be receiving or opening file types with extensions .exe, .dll, .scr, or .class. According to Symantec, these file types were used in more than 50% of last year’s spear phishing attacks.
  • If you’re still unsure that an email is legitimate, ask your company’s IT security folks.

Cyber best practices like these aren’t just for those who deal with security as part of their daily job duties. They need to be taught company-wide.

What kind of corporate policies and programs promote a healthy balance between paranoia and productivity?

I’ve heard of one corporate program where basic cybersecurity best practices are taught as part of the new hire training class for every employee. Another IT-run program periodically assesses its employees by sending fake phishing emails to different groups within the organization; those who fall for the faux scam by either opening an attachment or clicking a link are then required to take a cybersecurity seminar. The goal of these programs is to arm the company’s workforce with knowledge and deploy them as another layer of cyber defense.

Using the right tools to prevent attacks is key, and one of those tools is familiarity with the kinds of tactics cyber criminals are using, and how to recognize and avoid them. What processes or programs have you seen put in place that educates employees and encourages cyber scrutiny?

[Palo Alto Networks Blog]

Tracking New Ransomware CryptoWall 2.0

The latest development in the ransomware world is CryptoWall 2.0, a new version of this malware family that uses the Tor network for command and control.

F-Secure was the first to spot this new version on October 1, but since then the attacks have ramped up and new variants of the malware are emerging daily. Our WildFire analysis platform has picked up 84 CryptoWall 2.0 variants since September 30, delivered primarily through e-mail attachments but also through malicious PDFs and web exploit kits.

CryptoWall 2.0 is similar to other ransomware attacks that have plagued users and businesses for nearly a decade. Once it is running on a system, CryptoWall 2.0 seeks out document files and encrypts them using the RSA encryption algorithm. The attacker holds the key necessary to decrypt the files unless the victim agrees to pay a $500 ransom.

Unlike previous versions of CryptoWall, 2.0 communicates with its command and control (C2) server through the Tor anonymization network. This allows attackers to hide their communications and avoid having their C2 servers shut down, but also makes it easy for organizations to block the threat. CryptoWall isn’t the only threat that communicates over Tor and if your network doesn’t have an explicit reason to allow anonymization networks, you should consider blocking the application altogether with your firewall.

If your system has already been infected with CryptoWall 2.0, you’ll see a pop-up just like this one shortly after the malware has encrypted your documents.

Note that the attacker has given you a few options for how to pay them the ransom. The green box contains four links that will work only for your system. These use four domains registered just today:

  • torpaycash.com
  • torpaycnf.com
  • torpayeur.com
  • torpayusd.com

All of the domains currently resolve to 151.248.115.146, a Russian IP address and have WhoIs records associated with the e-mail address “ladomfichisi1987@mail.ru”. This is the same address used to register two other payment domains registered earlier this month:

  • tor2pay.com
  • tor4pay.com

If these domains are confiscated or otherwise shut down, CryptoWall instructs the user to download the Tor Browser and access a website (paytordmbdekmizq.onion) that is only accessible over the Tor network.

Unlikely some of it’s more flexible competition, CryptoWall only accepts ransom in the form of BitCoin. To pay the ransom the user will need to acquire 1.33 BitCoins and transfer them to a specific BitCoin wallet that is associated with their specific infection.

History has shown that paying the ransom will likely allow you to retrieve your files, but the best defense against ransomware is having up-to-date back-ups or by preventing the infection all-together.

Infection Vectors

Since we detected the first CryptoWall 2.0 variant with our WildFire engine on September 29, we’ve seen over 85,000 separate attacks attempting to deliver the malware. The majority of these have come through e-mails with executable attachments, sometimes contained in .zip files. Most of the e-mail attacks used fake invoice, fax and voicemail themes with attachments named like the following:

  • Complaint_IRS-Id-12839182.scr
  • fax00415741732781728.scr
  • VOICE387-778-3454.zip
  • CH_Import_Information.exe

In the last week we’ve seen the attack vectors evolve to contain exploit kits as well. On October 19, the Kafeine posted a blog discussing the inclusion of CVE-2014-0556 in the Nuclear Pack exploit kit, which was installing CryptoWall 2.0.

Yesterday we picked up an e-mail campaign pretending to be a fax report that carried a .zip attachment with a PDF inside. The PDF  exploits CVE-2013-2729 to download a binary which also installed CryptoWall 2.0.

Protecting Yourself

The best way to protect yourself against ransomware is to keep up-to-date backups of your important files. A ransomware infection, which encrypts all of your files, is similar to a drive failure, except that for a small fee you have the chance to get your files back.

To protect against CryptoWall 2.0 we recommend taking the following actions:

  • Block downloads of executable files from the web without specific user consent.
  • Add a ‘continue’ page for all file downloads that can provide a reminder to users before they automatically install potentially impacting software.
  • Employ an advanced detection system (like WildFire) to analyze all incoming executables, PDF files, and Microsoft Office Documents.
  • Consider blocking the Tor application completely within your network unless it’s absolutely necessary.
  • Ensure that only necessary users have write-access to network shares. CryptoWall will encrypt files in network shares if the share is mounted at the time of infection and accessible to the logged-in user.
  • Disconnect or unmounts back-up drives when they aren’t being used, as CryptoWall can also encrypt your backups.
  • Consider deploying an end-point protection system (like Traps) that prevents exploitation of known and unknown vulnerabilities.
  • Deploy IPS signatures to detect CVE-2014-0556 and CVE-2013-2729 exploitation. For Palo Alto Networks IPS users these include:
Sig ID Name CVE ID
35811 Adobe Reader Embedded BMP Parsing Integer Overflow Vulnerability CVE-2013-2729
36762 Adobe Flash Player Memory Corruption Vulnerability CVE-2014-0556
36763 Adobe Flash Player Memory Corruption Vulnerability CVE-2014-0556
36764 Adobe Flash Player Memory Corruption Vulnerability CVE-2014-0556
36754 Adobe Flash Player Memory Corruption Vulnerability CVE-2014-0556
 [Palo Alto Networks Blog]

 

English
Exit mobile version