Living With the Paradox of PCI DSS

With the next generation of customers embracing the use of new technologies, the use of “dirty money” is becoming less popular. In its place, people are increasingly choosing to use payment cards.

Problem:
This makes for some difficult decisions and consequences for merchants. If they choose not to embrace taking payments by payment card, they likely miss out on customer revenues. If they opt to take payments via payment cards, they have a duty to their acquiring banks, and even more importantly to their customers, to ensure that these payments are as secure as they can be.

However, the experience of trying to ensure that level of security is frequently perceived as extremely complex, difficult to achieve, time consuming, extremely expensive and near on impossible to maintain. Given that the supporting environments are extremely dynamic, it is a “war of attrition” trying to defend against ever-changing attacker tactics and involving multitudes of varying factors (technology, people and processes).

Cause:
The increasing preference for paying for goods and services via a piece of plastic or technology makes for a greater attraction to the criminal underworld, whether from organised crime or the opportunist hacker. If a business has not identified a vulnerability in its payment card business operations, it is very likely that a hostile entity soon will.

Securing the payment card data life cycle becomes increasingly difficult when you consider the potential attack and vulnerability vectors:

Front-end operations:

  • eCommerce web pages
  • Mail order, telephone orders (MOTO)
  • Point of sale (POS) systems
    • PIN transaction security (PTS) devices
    • Contactless
    • Mobile
  • Automated teller machines (ATMs)
  • Receipts
  • Found payment cards

Back-end operations:

  • Networks
  • Systems
  • Storage
    • Databases
    • Files
    • Paper
      • Receipts
      • Chargebacks
    • CCTV
    • Call recordings
    • Backups
  • Transmissions
  • Vulnerability management
  • Change control
  • Software development
  • Access control
  • Data centers
  • Monitoring systems use
  • Security testing

Kinetic (external) attack vectors:

  • Organized crime
  • Opportunist hackers
  • Foreign intelligence services
  • Cyber terrorism
  • Industrial espionage

Non-kinetic (internal) attack vectors:

  • Insider Threats
    • Deliberate actions by authorized persons
    • Negligent actions by authorized persons
    • Accidental actions by authorized persons

When you start adding all these together, plus all the connecting infrastructures of a business’s payment card operations, it becomes instantly apparent just how difficult securing these operations can be. The figure below shows a simplistic overview of how a typical business’s payment card operations might look. However, in reality this is often far more complex.

Actions
To help businesses improve their payment card operations, the card brands and the PCI Security Standards Council have produced a suite of controls that provides a baseline upon which a foundation of secure operations may be forged.

In truth, without prior specialist knowledge and skills, this can be extremely difficult to successfully achieve. This can be likened to expecting anyone to be able to build a house, having given them all the tools and materials they need (sand, cement, water, bricks, tools, etc.). However, in truth, this is rarely the case and, in reality, such a scenario would often lead to the application of expensive underpinning or to even demolish the building and start again.

Consequently, before commencing any sort of improvements to any existing payment card operations, it is essential that businesses familiarize themselves with the latest version of the Payment Card Industry Data Security Standard (PCI DSS) and engage with a reputable and experienced PCI DSS professional (PCI Qualified Security Assessor [QSA]).

Additionally, ISACA has just produced an extremely informative PCI DSS guide A Practical Guide to the Payment Card Industry Data Security Standard (PCI DSS), covering a comprehensive overview of PCI DSS and some of its associated complexities. It provides valuable support for anyone involved in delivering secure card payment operations and meeting the high standards required for PCI DSS compliance.

Net Benefits
It goes without saying that PCI DSS compliance is essential for the protection of a business’s payment card operations and to help safeguard customers’ payment card details. The popularity of paying products and services via a payment card is only going to increase. Consequently, having a well-planned and implemented compliance framework is critical to the success or failure of any such projects.

Having access to ISACA’s useful reference guide and the continued support from a trusted and knowledgeable QSA will help ensure, amongst others, the following benefits:

  • Improved security
  • Improved understanding
  • Informed decision making
  • Better alignment with business strategy
  • Efficiency
  • Timely progress
  • Cost-savings
  • Clarity
  • Success
  • Fines avoidance

James Seaman, CISM, CRISC
Senior Security Consultant, Nettitude Inc.

[ISACA Now Blog]

Frost & Sullivan Recognises Palo Alto Networks as Network Security Vendor of the Year in Australia

Last week, Palo Alto Networks received the 2015 Australia Network Security Vendor of the Year award from Frost & Sullivan. Armando Dacal, vice president for Palo Alto Networks Australia/New Zealand, attended the awards banquet in Sydney to accept the award.

The awards recognise ‘exemplary practices and best-in-class companies’ in Australia, across four markets, including ICT, Healthcare, Energy and Environment, Chemicals and Materials. This year was particularly special as it marked the 10th year that Frost & Sullivan hosted the excellence awards in Australia to recognise and celebrate exemplary practices and best-in-class companies in the country.

What a great way to close 2015. Congratulations Australia team!

Armando Dacal, vice president for Palo Alto Networks Australia/New Zealand

[Palo Alto Networks Blog]

Mobile Security: Variations on a Theme

Niccolò Paganini’s Caprice No. 24 in A Minor is a famous and notoriously difficult composition that only the most advanced violinists can play. It’s made up of a theme, along with Paganini’s own variations. But as respectable as it is on its own, it’s been discovered and rediscovered by a large number of composers and artists over the years for new audiences, many of whom may not have realized they were listening to Paganini in the first place.

Each variation on a theme can provide new insights, because they challenge the audience to hear things that they may not have otherwise noticed. But without knowledge of the original theme, there’s also a chance of missing out on the big picture. In some ways, the discussion around mobile security takes on its own variations of a theme, because many people share common concepts on risk but their priorities on what must be done vary greatly.

I’ve had discussions with people who see mobile security as a data at rest issue, namely how to protect and remove data once it reaches the mobile device. That argument may address some of the issues with lost and stolen devices, but it does not address what happens if there is a malicious adversary trying to control the device.

Then there are networking teams who see mobile security as a network blocking issue, namely that they’ll do whatever they can to keep BYOD and unsanctioned devices off their corporate network. That may be a way to keep infected mobile devices out of sight, out of mind, but it doesn’t really make the sanctioned devices any safer to use.

There are also networking teams who see mobile security as being a remote access issue, but as applications move to the cloud, the use case for remote access becomes fuzzy, and the use of standalone VPN appliances even fuzzier.

It’s important to ask whether you’re addressing the problem itself, or a variation of the problem. For example, while each of the problems above are valid in their own right, the bigger issue is that organizations often lack ways to enforce security policies that could prevent improper application traffic and threats from reaching the device in the first place.

These thoughts come to mind as I read through NIST Special Publication 1800-4, which outlines the problem in mobile security. Section 4.4.1 discusses threats (including mobile malware) and Section 4.4.2 discusses exploitable vulnerabilities, both of which are at the heart of modern cyberattacks.

At Palo Alto Networks, we believe that prevention is a necessary and critical measure to prevent exploits and malware from reaching the device in the first place. The next-generation security platform provides an integrated approach toward the use of global threat intelligence to stop threats in application traffic. With GlobalProtect, all corporate application traffic is inspected by the next-generation security platform, regardless of where the user is located. This enables the organization to take a prevention-first approach by applying security policy to stop both known and unknown mobile threats.

As mobile security becomes better understood, it is important to develop strategies and frameworks that will help foster broader understanding of the issues at play – not just one or two variations. Stopping threats won’t come from solving the variations of the theme, but rather by addressing the core of the problem itself. Plan for prevention first in order to strengthen your mobile security strategy.

[Palo Alto Networks Blog]

2016 Predictions #7: Healthcare Technology Advances Will Open Up New Attack Vectors

This is the seventh in our series of cybersecurity predictions for 2016. Stay tuned for more through the end of the year.

2015 was a rough year for the healthcare industry – more than 112 million healthcare records were breached, according to the HHS breach portal. That’s nine times (9x) higher than 2014. C-level executives at healthcare organizations understand that cyberattacks can have a direct impact on patient care, but they still struggle to advance their security maturity to the point that other industries with a longer history of regulation (i.e., financial services) have reached.

2016 will prove to be a year of innovation for healthcare organizations as they rush to implement new technologies that enhance the patient experience, such as remote patient monitoring and video visits, while many of the same core information security challenges persist.

Here’s a look at my top 2016 predictions for the healthcare industry.

The number of breached healthcare records caused by sophisticated cybersecurity attacks will continue to increase

In addition to the fact that there were nine times (9x) more breached healthcare records in 2015 compared to 2014, the top six healthcare breaches in 2015 account for over 98 percent of the 112 million total breached records for the year. Each of the top six was caused by an advanced cyberattack. All signs indicate that sophisticated and targeted cyberattacks in the healthcare industry are increasing with a few of the largest breaches linked to China-sponsored attackers.

In 2016, we will continue to see an increased number of targeted cyberattacks, resulting in major breaches in the healthcare industry. The healthcare providers who will be least impacted are those who:

  1. Conduct regular end-user security training to reduce successful phishing.
  2. Enforce a robust threat and vulnerability management program to identify risks.
  3. Deploy an advanced integrated security architecture to prevent cyberattacks on the network, on the endpoint, and in the cloud.

The IoT revolution will take off in the healthcare industry

For those who don’t know, the Internet of Things (IoT) revolution will go mainstream in 2016. The IOT refers to the vast array of WiFi-enabled sensors that will be available to track everything from the level of milk in your fridge to the angle of your blinds, according to the time of day. According to Gartner, there will be 6 billion of them by 2018. The IoT revolution has many applications within the healthcare industry, including remote patient monitoring for high-risk patients and behavior modification to help with obesity and smoking problems. As these devices get smaller and less expensive, we will see more healthcare practices use them to treat patients.

I wrote a blog post recently in response to the FDA’s alert for all healthcare providers to stop using Hospira’s Symbiq drug infusion pump due to a cybersecurity vulnerability that presented a significant risk to patient safety – the first ever alert of its kind. Billy Rios is the name of the amateur security researcher who identified the vulnerability working out of his garage. This gives you an idea of the amount of research that has been conducted on medical devices (generally, very little). In my recent job as a security lead for a hospital network, I worked directly with multiple medical device manufacturers and was surprised at the extent to which medical device security is an afterthought.

If the IoT devices used in healthcare are produced in the same manner (innovation first, security as an afterthought) they are likely to be compromised by two types of attackers: those interested in profiting (by stealing health data) and those who desire to impact patient safety justbecause they can. The healthcare providers who will be least impacted are those who adopt strict security standards for their medical devices and make efforts to reduce risk by segmenting their network-connected medical devices.

Healthcare organizations will begin to move critical applications and infrastructure to the cloud

“Cloud” has been a buzzword in healthcare IT for years now as industry leadership strategizes to adopt such technology that has significant opportunities for cost savings, performance and scalability. 2016 will be a transition year for many healthcare organizations that will migrate a portion of their critical infrastructure and applications to the private cloud by the end of the year.

  • Big players in the EMR application space (e.g., Epic, Cerner, McKesson) will begin to offer cloud-hosted EMR solutions, and healthcare providers will start executing two-year plans to migrate their EMR to a fully managed private cloud service model.
  • Healthcare providers will begin to deploy certain elements of critical infrastructure to cloud services like Amazon Web Services and virtualize things like Active Directory domain controllers and next-generation firewalls.
  • Cloud-based file sharing and collaboration sites like Box.com will become more prevalent in the healthcare industry, as users urge leadership to provide an easier method to share data.

Attackers will look to mobile devices as the next best vector into healthcare networks

In 2015, we saw a tremendous amount of spear phishing and email malware in the healthcare industry, but mobile devices are likely to be the next target. In a recent HIMSS survey, 90 percent of responders in the healthcare industry said they maintain mobile devices to engage patients in their organizations. Mobile devices in hospitals are often used to connect to EMRs and view PHI, which introduces a slew of risks, most notably: 1) The ability to connect to unsecured public Wi-fi allows eavesdropping, and 2) Normally benign mobile apps can be poisoned with malicious code, such as the recent discovery of XCodeGhost by Palo Alto Networks Unit 42, which allows the attacker to phish passwords and URLs through infected iPhone apps.

Healthcare is already a targeted industry for attackers, and mobile devices are becoming more integrated into patient care services. It’s only a matter of time before mobile devices become a popular vector to steal health records.

The best mitigation for the risks outlined in these healthcare cybersecurity predictions is a combination of improving both security processes and security technology. Read more about joining the community of 1100+ healthcare organizations who trust Palo Alto Networks to provide the technology required to prevent cyberattacks and protect patient care.

Have a happy and prosperous 2016!

Want to explore more of our top 2016 cybersecurity predictions? Register now for Ignite 2016.

[Palo Alto Networks Blog]

BackStab: Mobile Backup Data Under Attack from Malware

Today we are releasing a whitepaper describing how malicious actors are stealing private mobile device data by accessing local backup files stored on PC and Mac computers. We have identified 704 samples of six Trojan, adware and HackTool families for Windows® or Mac® OS X® systems that used this technique to steal data from iOS and BlackBerry® devices. These attacks have been in the wild for over five years, and we have observed them deployed in over 30 countries around the world.

Since these families use a common attack technique to access the backup files, we categorize all of them as using the “BackStab attack,” defined as “an attack approach that captures private mobile device data through the theft of local backup files stored on PC and Mac computers.”

The BackStab attack technique poses a risk to many mobile users for the following reasons:

  • The technique itself has been known to the security and forensic communities for over seven years. There are many publicly available articles and video tutorials describing how to conduct the attack using tools and/or open source projects available to the public.
  • Almost all private data stored in mobile devices can be stolen using this attack.
  • The attack doesn’t require the mobile device to be jailbroken or rooted.
  • The attack requires malware or adware running on PC or Mac, but doesn’t require the malware or adware to have any special privileges, such as root or administrator.
  • The attack requires at least one backup file to exist on the PC or Mac. In 
some situations, official backup software, like that of Apple iTunes, will automatically create backups of mobile devices without the user’s interaction and without encryption. It is also possible for malware to initiate a backup when the device is attached to an infected computer in some cases.
  • The attack is not theoretical and is occurring in the wild, as we have observed 704 malware samples in six Trojan, adware and HackTool families using it. Two of these families adopted the technique at least five years ago.
  • iOS and BlackBerry have been affected by real world attacks.

How BackStab Works

Under certain conditions, mobile devices automatically create un-encrypted backup files on a local computer when they are attached through a USB port. Apple iOS devices began doing this when iTunes backup was introduced with the first generation iPhone in 2007. When users choose the default backup options, the contents of their phone is stored, unencrypted on their computers local hard drive in a well-known location. Forensics experts have known about this behavior for years and have exploited it to gain access to iOS device content even when they cannot directly access an iPhone due to it’s strong protections.

Mitigate the BackStab Attack

As a successful BackStab attack allows a miscreant to steal almost all private data from a mobile device, we suggest users take the following actions (iOS is used as the example here):

  • Check all existing iTunes backups. If there are any unencrypted and unnecessary backups, delete them.
  • When using iTunes backup, always enable encryption with a strong, unique password.
  • When using iCloud backup, set a strong, unique password for the iCloud account, andenable two-step verification.
  • Upgrade the iOS system to newest version (i.e., iOS 9.1).
  • Don’t jailbreak your iOS device.
  • Before entering your Apple account and password in a web browser, carefully check the current website’s domain name and SSL certificate to ensure you’re visiting Apple’s official website.
  • When connecting the iOS device to an untrusted computer or charger via a USB cable, don’t click the “Trust” button in the dialog box that displays.
  • Use an antivirus product or service on your computer or in your network. This will be helpful to find and prevent some known malware families, such as DarkComet.

Palo Alto Networks has adopted these steps to protect our customers from the BackStab attack:

  • WildFire™ has added a new feature to detect possible BackStab attack behavior.
  • WildFire properly classifies all six families mentioned in this report as malware. When those samples are transferred through a network protected by our products, they will be blocked.
  • A public tag has been added to our AutoFocus service to identify potential BackStab attack behavior.
  • AutoFocus also has tags that identify the DarkComet RAT, although not all variants of this malware use BackStab.
  • Endpoints using Traps are protected from this threat through their connection to WildFire.

For complete details on this threat, please download the “BackStab: Mobile Backup Data Under Attack from Malware” whitepaper.

[Palo Alto Networks Blog]

English
Exit mobile version