***Welcome to ashrafedu.blogspot.com * * * This website is maintained by ASHRAF***

Posts

    Latest Updates

    Monday, May 23, 2022

    HTTP – Security

    HTTP stands for Hypertext Transfer Protocol, and it is a protocol – or a prescribed order and syntax for presenting information – used for transferring data over a network. Most information that is sent over the Internet, including website content and API calls, uses the HTTP protocol. There are two main kinds of HTTP messages: requests and responses.

    HTTP requests are generated by a user's browser as the user interacts with web properties. These HTTP requests all go to either an origin server or a proxy caching server, and that server will generate an HTTP response. HTTP responses are answers to HTTP requests.

    HTTP is used for communications over the internet, so application developers, information providers, and users should be aware of the security limitations in HTTP/1.1.

    Suggestions for reducing security risks are:

    Personal information

    Users must be very careful to prevent unintentional leakage of information via the HTTP protocol to other sources.

    HTTP cannot regulate the content of data that is transferred. HTTP cannot have any prior method to determine the sensitivity of any particular part of the information within the context of any request.

    All the confidential information should be stored at the server in encrypted form.

    Authors of services that use the HTTP protocol should not use GET based forms for the submission of sensitive data, because it will cause the data to be encoded in the Request-URI (Uniform resource identifier).

    File and Path Names Based Attack

    The documents returned by HTTP requests should be restricted to be only those that were intended by the server administrators.

    An HTTP server MUST disallow any such construct in the Request-URI, if it would otherwise allow access to a resource outside those intended to be accessible via the HTTP server.

    DNS Spoofing

    Clients using HTTP depend heavily on the Domain Name Service, and are thus generally prone to security attacks based on the deliberate mis-association of IP addresses and DNS names.

    Clients need to be cautious in assuming the continuing validity of an IP number/DNS name association.

    If the clients of HTTP cache the results of hostname lookups to improve the performance, they must observe the TTL information, which was reported by the DNS. When the IP address of the previously accessed server is changed, then the HTTP clients could be spoofed if they do not observe this rule.

    Authentication Credentials and Idle Clients

    Existing HTTP clients and user agents typically retain authentication information indefinitely. HTTP/1.1 does not provide a method for a server to direct clients to discard these cached credentials which are a big security risk.

    It is recommended to make the use of password protection in screen savers, idle time-outs, and other methods that mitigate the security problems inherent in this problem.

    Proxies and Caching

    Proxies have access to security-related information, personal information about individual users and organizations, and proprietary information belonging to users and content providers. Proxy systems should be protected as they contains or transports sensitive information.

    Caching proxies provide additional potential vulnerabilities, since the contents of the cache represent an attractive target for malicious exploitation. Therefore, cache contents should be protected as sensitive information.

    Web application security

    Web application security refers to a variety of processes, technologies, or methods for protecting web servers, web applications, and web services such as APIs from attack by Internet-based threats. Web application security is crucial to protecting data, customers, and organizations from data theft, interruptions in business continuity, or other harmful results of cybercrime.

    Web application security is a central component of any web-based business. The global nature of the Internet exposes web properties to attack from different locations and various levels of scale and complexity. Web application security deals with the security of websites, web applications and web services such as APIs.

    Common web application security vulnerabilities

    Attacks against web apps range from targeted database manipulation to large-scale network disruption. The most common attacks include:

    • Cross site scripting (XSS) - XSS is a vulnerability that allows an attacker to inject client-side scripts into a webpage in order to access important information directly, impersonate the user, or trick the user into revealing important information.
    • SQL injection (SQi) - SQi is a method by which an attacker exploits vulnerabilities in the way a database executes search queries. Attackers use SQi to gain access to unauthorized information, modify or create new user permissions, or otherwise manipulate or destroy sensitive data.
    • Denial-of-service (DoS) and distributed denial-of-service (DDoS) attacks - Through a variety of vectors, attackers are able to overload a targeted server or its surrounding infrastructure with different types of attack traffic. When a server is no longer able to effectively process incoming requests, it begins to behave sluggishly and eventually deny service to incoming requests from legitimate users.
    • Memory corruption - Memory corruption occurs when a location in memory is unintentionally modified, resulting in the potential for unexpected behavior in the software. Bad actors will attempt to sniff out and exploit memory corruption through exploits such as code injections or buffer overflow attacks.
    • Buffer overflow - Buffer overflow is an anomaly that occurs when software writing data to a defined space in memory known as a buffer. Overflowing the buffer’s capacity results in adjacent memory locations being overwritten with data. This behavior can be exploited to inject malicious code into memory, potentially creating vulnerability in the targeted machine.
    • Cross-site request forgery (CSRF) - Cross site request forgery involves tricking a victim into making a request that utilizes their authentication or authorization. By leveraging the account privileges of a user, an attacker is able to send a request masquerading as the user. Once a user’s account has been compromised, the attacker can destroy or modify important information. Highly privileged accounts such as administrators or executives are commonly targeted.
    • Data breach - Different than specific attack vectors, a data breach is a general term referring to the release of sensitive or confidential information, and can occur through malicious actions or by mistake. The scope of what is considered a data breach is fairly wide, and may consist of a few highly valuable records all the way up to millions of exposed user accounts.

    Wednesday, May 11, 2022

    Threat Management

    Cyber threat management is the process of identifying, analysing, evaluating and addressing an organisation’s cyber security requirements.

    Cyber threat management helps organisations prevent data breaches, but it also ensures that they’re equipped to deal with security risks when they do occur.

    The framework increases the collaboration between people, processes and technology, helping organisations detect and respond to incidents.       

    Organizations that successfully adopt and implement the threat management framework often benefit from:

    • Lower risk with faster threat detection, consistent investigations and faster response
    • Continuous improvement through built-in process measurement and reporting
    • Increased security team skills and effectiveness.

    Threat Management Challenges

    1. Lack of Visibility

    Security teams do not have complete visibility of their entire threat landscape with relevant context, including internal and external data sources. This lack of visibility is often caused by the conflict that exists between the lack of integration between point solutions, information technology security teams, and inconsistent processes throughout the organization.

    2. Lack of Insights and Necessary Reporting

    A security team does not necessarily have insight into specific KPIs (Key Point Indicators) that need to be tracking down. Additionally, there is no easy way to develop progress reports that identify maturity standards and compliance due to a lack of integration between the organization’s point solutions. 

    3. Skill Shortage

    Due to a skill shortage in the market, security leaders are having a difficult time hiring qualified talent and keeping the current staff motivated.

    It is also difficult to find additional staff budget, and security leaders have to find creative ways to “borrow” talent from other cross-functional units such as customer support, technical sales, etc. and then train them to be effective in the field.

    Practices for Effective Threat Management

     Effective threat management is achieved when the following framework is applied:

    • Insight: Insight into current threat operations with global services that can be tailored locally to meet the unique needs of an organization.
    • Visibility: Visibility into the threat landscape, inside and out, with services to test cyber resiliency and technology that can integrate security and non-security data sources.
    • Detection: Detection of the most critical threats to an organization through integrations of AI, threat intelligence and attack models derived from years of experience securing top Fortune 500 companies.
    • Investigation: Investigation assisted by AI and advanced analytics across structured and unstructured data sources along with multiple degrees of separation correlation capabilities.
    • Response: Response that delivers automated actions against the most common threats and dynamic business-wide playbooks that offer orchestration across people, processes and technologies.

    As organizations continue to struggle with increasingly frequent and complex attacks, it is essential for them to unite people, process and technology to stop threats faster and more efficiently. Threat management provides a great framework to deliver insights into the threat landscape, help organizations detect threats faster, investigate intelligently with AI and advanced analytics, and remediate rapidly with orchestration and automation.

    Scanning

    Scanning is a set of procedures for identifying live hosts, ports, and services, discovering Operating system and architecture of target system, Identifying vulnerabilities and threats in the network. Network scanning is used to create a profile of the target organization.

    Security scanning, or vulnerability scanning, can be simply described as scanning the security of a website, web-based program, network, or file system for either vulnerabilities or unwanted file changes. 

    Server security scanning is a type of preventative maintenance that needs to be conducted on a regular basis. As a result of network security issues, servers are very often put at risk. Examples of server types that need to be monitored are exchange servers, proxy servers, web servers, file servers, print servers, application servers, and many more.

    Network scans work by running vulnerability tests on network components. The tests look for faulty settings in the machines connected to the network, the router, and the servers themselves. The tests look for misconfigured internet protocols, server settings, weak passwords, and much more.

    Incident Response

    Incident response (IR) is a set of information security policies and procedures that can be used  to identify, contain, and eliminate cyberattacks. The goal of incident response is to enable an organization to quickly detect and halt attacks, minimizing damage and preventing future attacks of the same type.

    Incident Response Steps: 6 Phases of the Incident Response Lifecycle

    Preparation: 

    This step includes developing of policies and procedures to follow in the event of a cyber breach. This includes determining the exact composition of the response team and the triggers to alert internal partners. Key to this process is effective training to respond to a breach and documentation to record actions taken for later review.

    Identification: 

    This step is the process of detecting a breach and enabling a quick, focused response. IT security teams identify breaches using various threat intelligence streams, intrusion detection systems, and firewalls.

    During this phase, after an incident is confirmed, communication plans are also typically initiated. These plans inform security members, stakeholders, authorities, legal counsel, and eventually users of the incident and what steps need to be taken.

    Containment: 

    One of the first steps after identification is to contain the damage and prevent further penetration. This can be accomplished by taking specific sub-networks offline and relying on system backups to maintain operations.

    Containment is often accomplished in sub-phases:

    • Short term containment—immediate threats are isolated in place. For example, the area of your network that an attacker is currently in may be segmented off. Or, a server that is infected may be taken offline and traffic redirected to a failover.
    • Long term containment—additional access controls are applied to unaffected systems. Meanwhile, clean, patched versions of systems and resources are created and prepared for the recovery phase.

    Eradication: 

    This stage involves neutralizing the threat and restoring internal systems to as close to their previous state as possible. This can involve secondary monitoring to ensure that affected systems are no longer vulnerable to subsequent attack.

    Once teams are aware of all affected systems and resources, they can begin ejecting attackers and eliminating malware from systems. This phase continues until all traces of the attack are removed. In some cases, this may require taking systems off-line so assets can be replaced with clean versions in recovery.

    Recovery: 

    Security teams need to validate that all affected systems are no longer compromised and can be returned to working condition. This also requires setting timelines to fully restore operations and continued monitoring for any abnormal network activity. At this stage, it becomes possible to calculate the cost of the breach and subsequent damage.

    Lessons Learned: 

    One of the most important and often overlooked stages. During this stage, the incident response team and partners meet to determine how to improve future efforts. This can involve evaluating current policies and procedures, as well specific decisions the team made during the incident. Final analysis should be condensed into a report and used for future training.

    ·         Incident Response Team

    An incident response team is a team responsible for enacting your IRP(Incident Response Plan). This team is sometimes also referred to as a computer security incident response team (CSIRT), cyber incident response team (CIRT), or a computer emergency response team (CERT).

    The key duties of your CSIRT are to prevent, manage, and respond to security incidents. This can involve researching threats, developing policies and procedures, and training end users in cybersecurity best practices.

    An IRP(Incident Response Plan) is a set of documented procedures detailing the steps that should be taken in each phase of incident response. It should include guidelines for roles and responsibilities, communication plans, and standardized response protocols.

    Intrusion detection system (IDS)

    An intrusion detection system (IDS) is a system that monitors network traffic for suspicious activity and alerts when such activity is discovered. It is a software application that scans a network or a system for the harmful activity or policy breaching. 

    Intrusion prevention systems monitor network packets inbound the system to check the malicious activities involved in it and at once send the warning notifications.

    While anomaly detection and reporting are the primary functions of an IDS, some intrusion detection systems are capable of taking actions when malicious activity or anomalous traffic is detected, including blocking traffic sent from suspicious Internet Protocol (IP) addresses.

    Different types of intrusion detection systems: 

    Network intrusion detection system (NIDS) 

    A network intrusion detection system (NIDS) is deployed at a strategic point or points within the network, where it can monitor inbound and outbound traffic to and from all the devices on the network.

    Host intrusion detection system (HIDS)

    A host intrusion detection system (HIDSruns on all computers or devices in the network with direct access to both the internet and the enterprise's internal network. A HIDS has an advantage over an NIDS in that it may be able to detect anomalous network packets that originate from inside the organization or malicious traffic that an NIDS has failed to detect.

    A HIDS may also be able to identify malicious traffic that originates from the host itself, such as when the host has been infected with malware and is attempting to spread to other systems.

    Protocol-based Intrusion Detection System (PIDS)

    Organizations set up a Protocol-based Intrusion Detection System at the front end of the server. It interprets the protocols between the server and the user. PIDS monitors the HTTPS server regularly to secure the web. Similarly, it allows the HTTP server which is related to the protocol.

    Application Protocol-based IDS (APIDS)

    APIDS is set up within a group of servers. It interprets communication with the applications within the server to detect the intrusion. It identifies the intrusions by monitoring and interpreting the communication on application-specific protocols.

    Hybrid Intrusion Detection System

    Hybrid Intrusion Detection system is a mixture of two different IDS. Hybrid System develops a network system by combining host agents with network information. In conclusion, Hybrid System is more responsive and effective as compared to other IDS.


    Types of Intrusion Detection Systems Methods

    There are two main Intrusion Detection methods to identify malicious attacks or intrusion.

    1. Signature-based Intrusion Detection Method

    The IDS developed the Signature-based intrusion detection method to examine the network traffic and to detect attack patterns.

    Signature-based IDS detects the attacks on the basis of the specific patterns such as number of bytes or number of 1’s or number of 0’s in the network traffic. It also detects on the basis of the already known malicious instruction sequence that is used by the malware. The detected patterns in the IDS are known as signatures.

    Signature-based IDS can easily detect the attacks whose pattern (signature) already exists in system but it is quite difficult to detect the new malware attacks as their pattern (signature) is not known.

    2. Anomaly-based Intrusion Detection Method

    Organizations use the anomaly-based intrusion detection method to identify new and unknown suspicious attacks and policy breaching which the Signature-based detection method cannot identify easily.

    In anomaly-based IDS there is use of machine learning to create a trustful activity model and anything coming is compared with that model and it is declared suspicious if it is not found in model.

    3. Hybrid Detection Method

    A Hybrid method uses both Signature and Anomaly-based intrusion detection methods together. However, the main reason behind the development of a hybrid detection system is to identify more potential attacks with fewer errors


    Benefits of intrusion detection systems

    Intrusion detection systems offer organizations several benefits, starting with the ability to identify security incidents.

    An IDS can be used to help analyze the quantity and types of attacks. Organizations can use this information to change their security systems or implement more effective controls.

    An intrusion detection system can also help companies identify bugs or problems with their network device configurations. These metrics can then be used to assess future risks.

    Monday, May 9, 2022

    Ethical Hacking

    Ethical Hacking is an authorized practice of bypassing system security to identify potential data breaches and threats in a network. 

    Ethical hacking is a subpart of cyber security. It involves finding vulnerabilities and reporting them to the system’s owner.

    Ethical hackers hack into the system to find the flaws in the system and keep it safe.

    Ethical hackers aim to investigate the system or network for weak points that malicious hackers can exploit or destroy. They collect and analyze the information to figure out ways to strengthen the security of the system/network/applications.

    Type of Hackers

    i. “White Hat” hacking – practice of ethical hacking

    ii. “Black Hat” hacking describes practices involving security violations. The Black Hat hackers use illegal techniques to compromise the system or destroy information.

    iii. “Grey Hat” hacking - “Grey Hat” hackers don’t ask for permission before getting into your system. But Grey Hats are also different from Black Hats because they don’t perform hacking for any personal or third-party benefit. These hackers do not have any malicious intention and hack systems for fun or various other reasons, usually informing the owner about any threats they find. Grey Hat and Black Hat hacking are both illegal as they both constitute an unauthorized system breach, even though the intentions of both types of hackers differ.

    Ethical Hacker Roles and Responsibilities

    Ethical Hackers must follow certain guidelines in order to perform hacking legally.

    The most important rules of Ethical Hacking:

    • An ethical hacker must seek authorization from the organization that owns the system. Hackers should obtain complete approval before performing any security assessment on the system or network.
    • Determine the scope of their assessment and make known their plan to the organization.
    • Report any security breaches and vulnerabilities found in the system or network.
    • Keep their discoveries confidential. As their purpose is to secure the system or network, ethical hackers should agree to and respect their non-disclosure agreement.
    • Erase all traces of the hack after checking the system for any vulnerability. It prevents malicious hackers from entering the system through the identified loopholes.

    Phases of Ethical Hacking

    The five phases of ethical hacking (not necessarily a hacker has to follow these 5 steps in a sequential manner) are:

    Phase 1: Reconnaissance 

    This phase is also called as Footprinting and information gathering Phase, and int this phase hacker gathers information about a target before launching an attack.  It is during this phase that the hacker finds valuable information such as old passwords, names of important employees.

    Footprinting is a method that used for collecting data from target system. These data include important areas such as:

    1. Finding out specific IP addresses
    2. TCP and UDP services
    3. Identifies vulnerabilities

    There are also other ways to do footprinting, including impersonating a website by mirroring it, using search engines to find information about the organization, and even using the information of current employees for impersonation. 

    Phase 2: Scanning 

    In this phase, hackers are probably seeking any information that can help them perpetrate attack such as computer names, IP addresses, and user accounts. In fact, hacker identifies a quick way to gain access to the network and look for information. This phase includes usage of tools like dialers, port scanners, network mappers, sweepers, and vulnerability scanners to scan data.

    Basically, at this stage, four types of scans are used:

    1. Pre-attack: Hacker scans the network for specific information based on the information gathered during reconnaissance.
    2. Port scanning/sniffing: This method includes the use of dialers, port scanners, and other data-gathering equipment.
    3. Vulnerability Scanning: Scanning the target for weaknesses/vulnerabilities.
    4. Information extraction: In this step, hacker collects information about ports, live machines and OS details, topology of network, routers, firewalls, and servers.

    Phase 3: Gaining Access

    At this point, the hacker has all the information to attack. The hacker gains access to the system, applications, and network, and escalates their user privileges to control the systems connected to it.

    Phase 4: Maintaining Access 

    Once a hacker has gained access to the system, they keep that access for future exploitation and attacks. The hacker secures access to the organization’s Rootkits and Trojans and uses it to launch additional attacks on the network.

    The hacker from this point creates a new administrator account for themselves based on the naming structure and tries to blend in. 

    Phase 5: Clearing Tracks

    An intelligent hacker always clears all evidence so that in the later point of time, no one will find any traces leading to hacker.

    A hacker clears his traces by

    1. Clearing the cache and cookies
    2. Modifying registry values
    3. Modifying/corrupting/deleting the values of Logs
    4. Clearing out Sent emails
    5. Closing all the open ports
    6. Uninstalling all applications that he/she be used

    Network session analysis

    Network session analysis Network session analysis is a method of monitoring network activity and availability to identify issues, such as ...