Please Add Me to Your LinkedIn Network

Every day we send and receive requests to connect to people we know on social networks. LinkedIn is the world’s largest professional network with 300 million members in over 200 countries and territories around the globe. It is a great platform to develop and cultivate business connections, but can be rife with deceit and fraud. Fraudsters also use the platform as a social engineering tool, allowing them to connect with professionals and try to lure them into disclosing their real contact details – work email is always best – and then use this email address to send spam, or worse, deliver malware.

When discussing these potential pitfalls with a group of executives recently, I talked about people’s willingness to interact with strangers on sites, such as LinkedIn, potentially revealing sensitive information or otherwise exposing themselves or their employers to scams. An example I took them through was a paper by Thomas Ryan of Provide Security, who set up a profile of a fictitious person named Robin Sage on LinkedIn, Facebook and Twitter.

The profile described Robin Sage as “a flirtatious 25-year-old woman working as a ‘cyber threat analyst’ at the U.S. Navy’s Network Warfare Command.” The paper [1] Thomas Ryan wrote about the experiment and how he used the Robin Sage profile to establish connections with “executives at government entities such as the NSA, DoD and Military Intelligence groups. Other friends came from Global 500 corporations. Throughout the experiment Robin was offered gifts, government and corporate jobs, and options to speak at a variety of security conferences.” Thomas concluded that, “the propagation of a false identity via social networking websites can be rampant and viral.”

Some of the executives were intrigued, but others believed that they couldn’t be fooled. So I decided to walk through them a live example of identifying a fraudster on LinkedIn.

I used a previous invitation request I received and took a look at the profile of a female claiming to be a “senior sales executive who can help me generate more sales leads.” The profile looks detailed and complete with more than 500 connections and even the profile picture looked legitimate. A Google Search for her name and company yield very little. Still suspicious, I use the website whoisology.com to do some vetting on the email address and associated website listed on her profile page. All of these are non-existent.

In further review of the profile, I suspect that the LinkedIn profile photo is not what it may seem, so I use the Reverse Image Search [2] from Google to see what similar photos exist, which results in a surprising find. The same photograph has been used for multiple LinkedIn accounts with different names. All the roles are similar in nature; some even purport to be recruiters.  I also find links to an app on both the Google and Apple app stores, for a secure phone call application. One of the screen shots of the app is the same photo as the LinkedIn profile. This is clearly a case of someone reusing someone else’s photo.

There is no one single method to spot a fake account, though sometimes being a little bit suspicious helps. Here are some tips:

  • First, the invitation will probably just contain the canned text mentioned above or some other generic text.
  • Always check the profile before accepting an invitation, and do so via the LinkedIn message mechanism, not via the email received, as fake LinkedIn emails can cause more harm than checking.
  • There may be simply illogical conditions. Why would someone with a degree from a top school or university, with a good job title and years of experience, have only a few connections, and now be asking you, a stranger, to connect?
  • The profile might not have a photo, or the photo may be stolen from somebody else. Use the Google Image Search technique to see if it is a fake photo with a single click (sometimes).
  • The profile may be incomplete, it may have misspellings (even in job titles), or the name might not be capitalized properly.

The nature of online social networking involves people establishing connections without having the opportunity to establish the person’s authenticity. This requires taking a leap of faith, which can easily be exploited by scammers. Think about the type of information you have posted in your profile, and ask yourself, “Have I given away too much information about myself and my company?” All too often I have seen security professionals who profess to not telling anyone the controls they have deployed in the environment, to the virtual world where they have no problem stating what solutions they manage or have implemented in their current organization. Care should be given to ensure that we are not making it even easier for cyber attackers to enter our places of employment.

[1] http://media.blackhat.com/bh-us-10/whitepapers/Ryan/BlackHat-USA-2010-Ryan-Getting-In-Bed-With-Robin-Sage-v1.0.pdf

[2] https://support.google.com/websearch/answer/1325808?hl=en

[Palo Alto Networks Blog]

ISACA International President: The Power of Convenience

Convenience is a great motivator. The search for greater conveniences for businesses and consumers has created game-changing paradigm shifts. ATMs, online banking, movie streaming and even household appliances all transformed businesses. They opened up completely new markets, and at the same time, marked the end for businesses that didn’t innovate.

But each convenience, and each new service and technology comes with new, often uncharted risks. Mobile payments are no exception. The global mobile payment transaction market, including solutions offered by Apple Pay, Google Wallet, PayPal and Venmo, will be worth an estimated US $2.8 trillion by 2020, according to Future Market Insights.

These expectations are impressive and indicate that this is an area of potential growth and worth further exploration. A recent ISACA survey of more than 900 member security professional shows that an overwhelming majority (87%) expect to see an increase in mobile payment data breaches over the next 12 months, yet 42% of respondents have still used this payment method in 2015. The 2015 Mobile Payment Security Study suggests that people who use mobile payments are unlikely to be deterred by security concerns.

Other data from the survey show that cybersecurity professionals are willing to balance benefits with perceived security risks of mobile payments:

  • Only 23% believe that mobile payments are secure in keeping personal information safe.
  • Nearly half (47%) say mobile payments are not secure and 30% are unsure.
  • At 89%, cash was deemed the most secure payment method, but only 9% prefer to use it.

ISACA survey respondents also ranked the major vulnerabilities associated with mobile payments:

  1. Use of public WiFi (26%)
  2. Lost or stolen devices (21%)
  3. Phishing/shmishing (phishing attacks via text messages) (18%)
  4. Weak passwords (13%)
  5. User error (7%)
  6. There are no security vulnerabilities (0.3%)

According to those surveyed, currently the most effective way to make mobile payments more secure is using two ways to authenticate their identity (66%), followed by requiring a short-term authentication code (18%). Far less popular was an option that puts the onus on the consumer—installing phone-based security apps (9%).

All people using mobile payments need to educate themselves so they are making informed choices. You need to know your options, choose an acceptable level of risk, and put a value on your personal information. From my experience, the best tactic is awareness. Embrace and educate about new services and technologies.

Christos K. Dimitriadis, Ph.D., CISA, CISM, CRISC
ISACA International President

[ISACA Now Blog]

The Grapes of Career Path—Why Computer Science Graduates Need Cyber Certifications

“Why don’t you go on west to California? There’s work there, and it never gets cold. Why, you can reach out anywhere and pick an orange. Why, there’s always some kind of crop to work in. Why don’t you go there?”

John Steinbeck, “The Grapes of Wrath”

I am one of the lucky ones. After a few twists and turns along the way, I landed a great job in my chosen discipline (cybersecurity)—the field I spent four years of my life studying. Like many recent college graduates, however, I entered the workforce unwittingly unprepared. What I did not realize then is that a college degree was the barest minimum requirement—it was only a ticket to get me inside a hiring manager’s office. When I graduated Stevenson University with my Bachelor of Science degree in Computer Information Systems, I lacked something that cybersecurity mangers place a great deal of emphasis upon: a certification.

Today’s college students are inundated with articles that promise lucrative careers in IT, cybersecurity, and the tech sector. The seemingly wide-open job market, combined with our generation’s affinity for computers and the Internet, makes a computer science degree seem like a logical choice. Many students however, forget to read the fine print . Like Steinbeck’s Dust Bowl tenant farmers, who arrived in California’s Promised Land only to discover a near-hopeless situation, today’s entry-level graduates are smacked with the reality that most tech jobs require several years of experience and certifications.

For some, the best way to earn valuable experience is through a paid (or unpaid) internship at a tech company. It is true that stellar performance at an internship could ultimately lead to a full-time, salaried position. There is another way, however, for savvy job-seeking professionals to overcome some of their relative inexperience; they can earn certifications in their specialized field. Unlike the knowledge gained via college degree, which atrophies over time, cybersecurity certifications show potential employers that a candidate’s skills are current and, most importantly, relevant to the advertised job position.

Most of today’s cybersecurity certifications are designed to reflect current operational realities in the tech world. In particular, ISACA’s recently released CSX Practitioner certification requires candidates to demonstrate more than mere knowledge of advanced cybersecurity concepts; this new certification tests how candidates apply their knowledge and skills against an actual network. This means that a college graduate—who earns the CSX Practitioner certification—can level the playing field by demonstrating the same level of cybersecurity and network proficiency as a more experienced professional.

At first glance, my advice to entry-level graduates might seem unreasonable. Many graduates are already struggling with record levels of student loan debt; for them, the cost of cybersecurity certifications can be overwhelming. However, some federal and state-level programs in the US and similar programs around the world offer grants that cover the cost of cybersecurity certification trainingand testing. Joining an organization such as ISACA can provide reduced fees for cybersecurity certification and training. An added benefit to joining certification organizations is for young job seekers to network more effectively and to become a part of the cybersecurity discussion. ISACA’s local chapters frequently offer announcements for job openings on their respective websites.

Every day, I watch my company’s tech recruiters send out email after email looking for qualified candidates to place in cybersecurity job openings. The job descriptions all have one thing in common: they require some form of cyber certification and/or experience. For recent college grads, the path to cyber employment is not printed on a handbill, and, it does not necessarily lead to Silicon Valley. Nevertheless, earning a cybersecurity certification could make the road to a rewarding career far shorter and straighter.

Adeline Heuchan
Digital Forensics Instructor at TeleCommunication Systems, Inc.

[ISACA Now Blog]

First NextWave Huddle Webcast: What Did You Miss?

On Sept. 17, I hosted our first NextWave Huddle, a global channel partner webcast and a key component of my commitment to deliver more clear and consistent communications to you, our partners in FY16.

If you couldn’t attend, click here to listen to the replay and click here to review the presentation.

Together in FY15 we drove phenomenal results: we had nearly 500 partners double their business in FY15, we had more than 12,000 partner security professionals earn technology or sales certifications and we added a record-breaking, 2,000-plus new customers in Q4 FY15, bringing our total number of customers to more than 26,000 worldwide.

Make no mistake, we wouldn’t be the company we are today without you, our partners, and we can’t achieve our goal of becoming the largest enterprise security company in the next two years without expanding the scale and productivity of our partner ecosystem. To achieve this we will focus on three key pillars:

  1. Building a channel partner ecosystem that provides the coverage, capacity and capabilities to elevate our leadership position in the enterprise security market.
  2. Optimizing our channel programs, training, tools, systems & initiatives to strengthen partner differentiation & profitability.
  3. Remaining committed to those partners that are investing in us.

By focusing on these pillars we have an opportunity to drive unprecedented success, as long as we keep you aware and informed. With this in mind, let me highlight a couple of key items for Q1 FY16:

  • We have a new evaluation tool for you to use with customers, called the Security Lifecycle Review (SLR). Click here to download the Quick Start Guide for Partners today.
  • On Sept. 15, we announced Aperture, a new SaaS security offering. Make sure youunderstand Aperture and the opportunity to expand your security business.
  • We have a huge opportunity ($80B) to help transform the data center with VMware, make sure you understand the VMware NSX plus Palo Alto Networks
  • If you aren’t already, start following us on Twitter @NextWavePartner for real-time updates.

I couldn’t be more excited about the opportunity in front us. We are in the right market with the right strategy, philosophy, platform and partnerships. I am confident we are building a world class channels organization, which includes you, our partners, and look forward to accelerating together in FY16.

Go Palo Alto Networks.

[Palo Alto Networks Blog]

Why I’m Passionate About Prevention

In the last few years, a decades-old problem has taken on a new name: cyberattacks. This is now in the top five global risks in terms of impact and probability [1]. The reason for this is well-documented: attacks have become far more personalized, leveraging the techniques and tactics first seen in nation-state APT attacks. For cybercriminals, focusing on getting a hold of the golden nuggets that make each business uniquely profitable, such as intellectual property, businesses process, and data, has far greater impact than the traditional generic attacks.

Likewise, we are sprinting toward a hyper-connected society, and companies’ dependency on technology in order to function and be profitable is increasing. Concerns around BYOD are being overridden by concerns of the much broader Internet of Things, whether that is wearables, mobile payments or connected cars.

It’s easy to see why this has become a topic that is high on national and global risk registers. There is a growing perception that failure is inevitable, breaches will happen, and attackers will get in. My question is: are we giving in too easily?

Human nature means we make mistakes, but, more importantly, that we learn from them. One of the most significant traits we have is determination. We cannot and should not overly focus on recovery. We must find a better way to prevent the problem in the first place. While we accept that road accidents happen, we don’t focus only on emergency recovery services. Instead we continue to evolve the safety measures to prevent harm and loss of life. As such, a key motivation for my joining Palo Alto Networks was to work for a company that is resolutely focused on innovating solutions to stop cyber incidents from occurring.

So what does the next evolution of preventing successful cyberattacks look like? We can learn a lot from technology’s own evolution. Historically, technology was built with a purpose in mind, but the implementation all too often failed, as it was built by engineers for engineers. Usability has become the key to success – if we cannot intuitively use the technology today, the likelihood is that it will fail.

Over decades we have built a broad spectrum of security components that each solve parts of the problem, some of which, I would challenge, are no longer fit for this purpose, while others still have significant value. However, the major challenge is drawing these pieces of the security puzzle together to detect and block the attack. This is a requirement, as most incidents today leverage multiple components in their lifecycle, and the challenge is being able to piece together the jigsaw puzzle to see the entire picture, when so much information is being generated by so many component parts. We have effectively evolved to something so unwieldy and complex that it is unusable. Fragmented solutions, creating so much noise that we become immobile, take too long and use too much processing power to give the complete view, causing the solution to become ineffective.

If we are to be as agile and dynamic as the adversaries we face in cyberspace, we must focus on usability and automation because our most scarce resource is undoubtedly people. Time and efficacy must be key metrics, as should the ability to recognise and gather multiple indicators of modern attacks across the diverse IT ecosystem. It is also necessary to dynamically correlate these against our own and our peers’ intelligence to quickly and accurately stop an incident before harm occurs.

As cars went faster, safety had to evolve. At no point did we give up and simply get more ambulances or insurance; life is too precious. In the same way, the cyber world is becoming increasingly dynamic and precious to society. We should not accept that breaches have to occur, but should strive instead to evolve our capabilities to ensure a safe online experience.

[1] http://widgets.weforum.org/global-risks-2015-interactive/risk-explorer.html#landscape///

[Palo Alto Networks Blog]

English
Exit mobile version