Showing posts with label Security Research. Show all posts
Showing posts with label Security Research. Show all posts

Sunday, July 25, 2010

Digital Forensics Association Research Report: Five Years of Data Breaches

A new report from the Digital Forensics Association confirms the need for organizations to pay careful attention to all aspects of information security.The report "The Leaking Vault - Five Years of Data Breaches" analyzes over 2,800 data loss incidents from publicly accessible sources, with a known disclosure of 271.9 million records.  This study—the largest of its kind to date—provides analysis on which breach vectors carry the most risk, and should help provide organizations with more accurate information when combating this problem.


Key findings include:

  • Business, government, educational and medical organizations have been responsible for losing on average over 395,000 people's data per day every day for five years.  
  • Hacking was responsible for 45% of all exposed records with an average loss of 716,000 records
  • Stolen laptops were responsible for 49% of breaches but only 6% of lost records per incident.
  • The fastest growing attack vector is social engineering
  • Social Security Numbers (SSNs) are the most frequent data element reported.
  • The Business sector accounted for 70% of breach incidents

Thursday, May 13, 2010

Are Cars Next for Cybercriminals?

The New York Times reports that in a "paper, which will be presented at a computer security conference next week in Oakland, Calif., computer security specialists at the University of Washington and the University of California, San Diego, report that while modern cars have extensive safety engineering in the design of their computer control systems, little thought has been given to the potential threat of hackers who may want to take over the networks that increasingly control modern cars. ...The researchers asked what could happen if a hacker could gain access to the network of a car, said Tadayoshi Kohno, a University of Washington computer scientist. He said the research teams were able to demonstrate their ability to circumvent a wide variety of systems critical to the safety of drivers and passengers. ...They also demonstrated what they described as “composite attacks” that showed their ability to insert malicious software and then erase any evidence of tampering after a crash. ... The researchers were able to activate dozens of functions and almost all of them while the car was in motion."

Read the NY Times story.

Friday, April 30, 2010

NSA Reviews Future Cybersecurity Techniques, Technologies and Challenges

Brian Krebs reports on a 605 page National Security Association study from 2004. According to Krebs, the document "reads like a listing of the pros and cons for a huge array of defensive and counterintelligence approaches and technologies that an entity might adopt in defending its networks."


Read more and get the full report at KrebsOnSecurity.com ...

Tuesday, April 6, 2010

Researchers begin work on 'sophisticated' security for healthcare IT

Healthcare IT News reports that the Information Trust Institute (ITI) at the University of Illinois at Urbana-Champaign has received $15 million to lead a multi-university consortium of researchers to create technology that will make electronic health record systems and health data exchange secure enough to gain the confidence of doctors and patients.

Read the story at Healthcare IT News ...

Thanks to Hal Amens for this story.

Monday, December 28, 2009

GSM Cell Phone Encryption Broken

What's happening: At a conference in Berlin, German security researcher Karsten Nohl demonstrated a way to break system encryption to listen to conversations on GSM-based mobile phones. The encryption algorithm and variants of it are used to ensure the privacy of 80% of mobile calls.

What it means: Expect cell phone providers to strengthen GSM encryption algorithms.

What to do: While the fallout from this demonstration is not likely to put you at special risk, it is always a good idea to be circumspect in what you say on a mobile phone call.

**********************************
Cellphone Encryption Code Is Divulged