{"id":30089,"date":"2017-11-10T11:09:42","date_gmt":"2017-11-10T03:09:42","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=30089"},"modified":"2017-11-10T11:09:42","modified_gmt":"2017-11-10T03:09:42","slug":"opinion-the-new-hacker-who-are-they-what-they-want-how-to-defeat-them","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2017\/11\/10\/opinion-the-new-hacker-who-are-they-what-they-want-how-to-defeat-them\/","title":{"rendered":"OPINION | The new hacker \u2014 Who are they, what they want, how to defeat them"},"content":{"rendered":"<p><strong>By Alan Zeichick<\/strong><br \/>\n<strong>Tech Editor, NetEvents<\/strong><\/p>\n<p><strong>We are very fortunate, in many countries, to have law enforcement agencies that focus, as part of their mission, to deal with hacking as either crimes to be prosecuted, or as intelligence operations to be managed. We have law enforcement agencies and experts who are, themselves, CISOs, Chief Information Security Officers. We have people out there who spend their time educating, and teaching businesses how to be safe on social media, perhaps, or what to do when a breach happens, when to call the specialized cops to come and help.<\/strong><\/p>\n<div id=\"attachment_30091\" style=\"width: 632px\" class=\"wp-caption aligncenter\"><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/11\/hacking-1.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-30091\" class=\"size-full wp-image-30091\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/11\/hacking-1.jpg\" alt=\"\" width=\"622\" height=\"432\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/11\/hacking-1.jpg 622w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/11\/hacking-1-300x208.jpg 300w\" sizes=\"auto, (max-width: 622px) 100vw, 622px\" \/><\/a><p id=\"caption-attachment-30091\" class=\"wp-caption-text\">IMAGE FROM <a href=\"https:\/\/pixabay.com\/en\/hacker-cyber-crime-internet-2300772\/\">PIXABAY.COM<\/a><\/p><\/div>\n<p>Let\u2019s talk about the hackers, not through the eyes of industry, and not through the eyes of diplomats, but through the eyes of current and former U.S. law enforcement experts, whose job it is to run these people down and throw them in jail.<\/p>\n<h2>The Federal Bureau of Investigation<\/h2>\n<p>MK Palmore, an Information Security Risk Management Executive with the <a href=\"https:\/\/www.fbi.gov\/investigate\/cyber\">FBI\u2019s Cyber Branch<\/a> in San Francisco, runs the cyber-security teams assigned to the San Francisco division of the FBI. \u201cMy teams here in San Francisco typically play some part in the investigations, where our role is to identify, define attribution, and get those folks into the U.S. Justice system.\u201d<\/p>\n<p>Palmore noted that the \u201cFBI is 35,000-plus personnel, U.S.-based, and part of the Federal law enforcement community. There are 56 different field offices throughout the United States of America, but we also have an international presence in more than 62 cities throughout the world. A large majority of those cities contain personnel that are assigned there specifically for responsibilities in the cyber-security realm, and often-times are there to establish relationships with our counterparts in those countries, but also to establish relationships with some of the international companies, and folks that are raising their profile as it relates to international cyber-security issues.\u201d<\/p>\n<h2>The U.S. Secret Service<\/h2>\n<p>It\u2019s not <em>really<\/em> a secret: In 1865, the <a href=\"https:\/\/www.secretservice.gov\/\">Secret Service<\/a> was created by Congress to primarily suppress counterfeit currency. \u201cCounterfeit currency represented greater than 50% of all the currency in the United States at that time, and that was why the Agency was created,\u201d explained Dr. Ronald Layton\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Deputy Assistant Director U.S. Secret Service.<\/p>\n<p>\u201cThe Secret Service has gone from suppressing counterfeit currency, or economic, or what we used to refer to as paper crimes, to plastic, meaning credit cards. So, we\u2019ve had a progression, from paper, to plastic, to digital crimes, which is where we are today,\u201d he continued.<\/p>\n<h2>Protecting Data, Personal and Business<\/h2>\n<p>\u201cI found a giant hole in the way that private sector businesses are handling their security,\u201d said Michael Levin. \u201cThey forgot one very important thing. They forgot to train their people what to do. I work with organizations to try to educate people \u2014 we\u2019re not doing a very good job of protecting ourselves. \u201c<\/p>\n<p>A leading expert in cyber-security, Levin is Former Deputy Director, <a href=\"https:\/\/www.dhs.gov\/topic\/cybersecurity\">U.S. Department of Homeland Security\u2019s National Cyber-Security Division<\/a>. He retired from the government a few years ago, and is now CEO &amp; Founder of the <a href=\"https:\/\/www.cfisa.org\/\">Center for Information Security Awareness<\/a>.<\/p>\n<p>\u201cWhen I retired from the government, I discovered something,\u201d he continued. \u201cWe\u2019re not protecting our own personal data &#8211; so, everybody has a role to play in protecting their personal data, and their family\u2019s data. We\u2019re not protecting our business data. Then, we\u2019re not protecting our country\u2019s data, and there\u2019s nation states, and organized crime groups, and activists, that are coming after us on a daily basis.\u201d<\/p>\n<h2>The Modern Hacker: Who They Are, What They Want<\/h2>\n<p>There are essentially four groups of cyber-threat activists that we need to be concerned with, explained the FBI\u2019s Palmore. \u201cI break them down as financially-motivated criminal intrusion, threat actors, nation states, hacktivists, and then those security incidents caused by what we call the insider threat. The most prevalent of the four groups, and the most impactful, typically, are those motivated by financial concerns.\u201d<\/p>\n<p>Why? \u201cWe\u2019re talking about a global landscape, and the barrier to entry for most financially-motivated cyber-threat actors is extremely low,\u201d Palmore continued. \u201cIn terms of looking at who these folks are, and in terms of who\u2019s on the other end of the keyboard, we\u2019re typically talking about mostly male threat actors, sometimes between the ages of, say, 14 and 32 years old. We\u2019ve seen them as young as 14.\u201d<\/p>\n<p>Criminals? Nation states? Hacktivists? Insiders? While that matters to law enforcement, it shouldn\u2019t to individuals and enterprise, said CIFSA\u2019s Levin. \u201cFor most people, they don\u2019t care if it\u2019s a nation state. They just want to stop the bleeding. They don\u2019t care if it\u2019s a hacktivist, they just want to get their site back up. They don\u2019t care who it is. They just start trying to fix the problem, because it means their business is being attacked, or they\u2019re having some sort of a failure, or they\u2019re losing data. They\u2019re worried about it. So, from a private sector company\u2019s business, they may not care.\u201d<\/p>\n<p>Levin pointed out that, \u201cLaw enforcement cares, because they want to try to catch the bad guy. But for the private sector is, the goal is to harden the target. Many of these attacks are, you know, no different from a car break-in. A guy breaking into cars is going to try the handle first before he breaks the window, and that\u2019s what we see with a lot of these hackers. Doesn\u2019t matter if they\u2019re nation states, it doesn\u2019t matter if they\u2019re script kiddies. It doesn\u2019t matter to what level of the sophistication. They\u2019re going to look for the open doors first.\u201d<\/p>\n<p>The Secret Service cares almost exclusively about folks trying to steal money. \u201cSeveral decades ago, there was a famous United States bank robber named Willie Sutton,\u201d said Layton. \u201cWillie Sutton was asked, why do you rob banks? \u2018Because that\u2019s where the money is.\u2019 Those are the people that we deal with.\u201d<\/p>\n<p>Layton explained that the Secret Service has about a 25-year history of electronic crimes; the first electronic crimes taskforce was established in New York City 25 years ago. \u201cWhat has changed in the last five or 10 years? The groups worked in isolation. What\u2019s different? It\u2019s one thing: They all know each other. They all are collaborative. They all use Russian as a communications modality to talk to one another in an encrypted fashion. That\u2019s what\u2019s different, and that represents a challenge for all of us.\u201d<\/p>\n<h2>Priority #1: Training<\/h2>\n<p>If you lock your car doors, a criminal might break into someone\u2019s vehicle instead of yours. How can individuals and businesses do a better job locking their doors? It\u2019s human factors, said Levin. \u201cWell, if we look at the Equifax hack, which is so relevant in the news right now, it was a simple error that was made by not providing the right general basic security practices on a server. This was a problem 20 years ago, and it\u2019s still a problem today.\u201d<\/p>\n<p>\u201cHow do we get organizations to do the right patching and the right updates, and they\u2019re not being lazy when it comes to general security practices?\u201d he continued. \u201cEvery citizen, every country, every organization, needs to start figuring out a way to educate the population on how to protect themselves. It\u2019s not just technology. When we have employees who are automatically clicking on every single email they get, and clicking on every link, and opening every attachment, we can have the best technology in the world, but eventually, something\u2019s going to get through.\u201d<\/p>\n<p>Layton agreed that more training is needed. \u201cWe pay a lot of attention to what the bad guys will use to further their own illicit gain. They\u2019re very good at understanding human factors, and what folks will click on. We are starting to see an emerging field of people who come from the addiction community, who are starting to look at the relationships that we have with our phones and devices, as some kind of unusual behavior and attachment that mimics certain kinds of addictions.\u201d<\/p>\n<p>What ends up happening is, you are clicking on everything. That\u2019s why the technique of spearphishing is, in fact, so popular, and so efficacious, because you\u2019re curious. You want to see what is, in fact, behind that next click,\u201d Layton explained. \u201cOf course, when you look at the analysis, and the pathology, of how malware gets on a system, you\u2019re going to find that a major percentage comes from clicking on an email attachment. One of the counters to this is cyber hygiene training. If I\u2019m a company, and I\u2019ve got $10 to spend, 10 of those dollars are going to go to education.\u201d<\/p>\n<h2>Follow the Fundamentals<\/h2>\n<p>Every business does the fundamentals of good cybersecurity, right? Wrong. \u201cThe information security fundamentals are not as fundamental as we think,\u201d said Palmore.<\/p>\n<p>\u201cIn the post-mortems of investigations that my teams conduct,\u201d he continued, \u201cwe always find that there\u2019s some gap in the coverage of the security of that particular network that boils down to a fundamental issue of security protection, and we\u2019re talking about simply things like patch management. Audit and log management. Security and vulnerability assessments, and then adhering, or actually taking steps to correct those actions.\u201d<\/p>\n<p>These are obvious problems, Palmore explained. \u201cGetting buy-in from leadership and management that cybersecurity it is an important issue, an enterprise risk-management issue, and that you need to appoint folks, and then empower them to actually get the job done as it relates to increasing your security posture. That\u2019s essential. But time and time again, we find that folks are not doing that.\u201d<\/p>\n<p>Palmore focused on one particular fundamental: Two-factor authentication. \u201cTwo-factor authentication is an obstacle to threat actors,\u201d he said. \u201cIt is not insurmountable. So, if you are facing a highly, highly capable threat actor, it\u2019s not going to stop them from accomplishing their mission, but for what I call the line cyber threat actor, two-factor authentication represents an obstacle that, to them, is a waste of their time. They will move to a target that is easier for them to breach, or find an easier way to get into an identified target.\u201d<\/p>\n<p>\u201cIssues like that, among the topics like cyber hygiene, information security fundamentals,\u201d Palmore sighed. \u201cIf businesses and folks would be diligent about following those fundamentals, I tell you we would be in a better position than what we find ourselves in now.\u201d<\/p>\n<h2>New Methods, New Actors, for the Next Decade<\/h2>\n<p>While the fundamentals of good cybersecurity stay the same, the attackers and their methods can change. The Secret Service\u2019s Layton explained that the technological sophistication and capability of the threat actors has increased. \u201cThe toolsets that you see today that are widely available would have been highly classified 20 years ago. Sophistication has gone up exponentially.\u201d<\/p>\n<p>\u201cLook at ransomware. In 2014, ransomware was the 22nd most popular crimeware application. In 2017, it\u2019s number five. In 2014, when we saw this, the bad guys would say, I\u2019m going to encrypt your file unless you pay me whatever, X amount of dollars in Bitcoin, or something like that. What ended up happening is, end-users got smarter, and just said, well, I\u2019m going to back my systems up. Now ransomware starts to concentrate on either partial or full hard-disk encryption, so backup doesn\u2019t help as much. Sophistication by the threat actors has gone up, and the ability to more quickly adjust, on both sides, quite frankly, has gone up.\u201d<\/p>\n<p>There is also more ability to act anonymously \u2013 and thanks to Bitcoin, to extract money anonymously, explained the FBI\u2019s Palmore. \u201cThis issue of anonymity, and the ability for threat actors, again, to go into the Dark Web and exchange exploits, exchange information, and exchange currency with one another, allows for a level of activity, frankly, that we have not seen historically.\u201d<\/p>\n<p>\u201cTwenty years ago, when I came in the FBI, we were on the heels of finishing up the dismantlement of what we then called organized crime,\u201d he continued. \u201cNow, what we look at in terms of organized crime, or a criminal enterprise, is a organization with the ability of folks to connect, exchange information, make plans, conduct exploits, buy and purchase things from one another using digital currency. This completely changes the landscape, and it definitely makes it harder for us to align the dots and close the gap on investigations that we conduct.\u201d<\/p>\n<p>Encryption is going to be increasingly important for businesses in the future, said CIFSA\u2019s Levin. \u201cIn the private sector, the concept of encryption, and being able to encrypt your customers\u2019 data, is an important piece of the puzzle. One of the things that we see all the time is that people are sending emails in clear text with very sensitive information. People don\u2019t understand that sending emails are like sending a postcard.\u201d<\/p>\n<p>\u201cYou would never send a credit card number in a postcard,\u201d he joked. \u201cBut emails are exactly the same thing. They\u2019re going through the internet through servers that are not protected, in many cases, and the average citizen doesn\u2019t realize that. Fortunately, we are starting to see more organizations that are encrypting their email as regular practice.\u201d<\/p>\n<h2>Use the Hacker\u2019s Tools Against Them<\/h2>\n<p>Want to keep your corporate data private?<\/p>\n<p>\u201cAs the crooks get more sophisticated, the private sector needs to get more sophisticated,\u201d Levin concluded, \u201cand they can use the same tools that the bad guys are using to protect their customers\u2019 data, or their employees\u2019 data.\u201d<\/p>\n<p>Lock your doors. Practice the fundamentals. Encrypt your data. Train your users. Sounds like a good start, according to three top experts. So, what are you waiting for?<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Let\u2019s talk about the hackers, not through the eyes of industry, and not through the eyes of diplomats, but through the eyes of current and former U.S. law enforcement experts, whose job it is to run these people down and throw them in jail.<\/p>\n","protected":false},"author":7,"featured_media":30091,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[3800,54,96],"class_list":["post-30089","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-opinions","tag-hacking","tag-security","tag-technology"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/30089","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=30089"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/30089\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/30091"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=30089"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=30089"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=30089"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}