Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Sometimes when tech policymakers try to solve a problem, their proposed cure would only make matters much worse. That’s certainly the case with draft US legislation that would give victims of cyberattacks the chance to hunt their suspected attackers down. . Known as the Active Cyber Defense Certainty Act, or ACDC for short, the bill aims to let victims try to track down attackers by entering the systems of organizations they suspect the hackers have used to mount assaults. Often, these organizations may be other companies that are unaware their computers have been compromised. An existing US law forbids this kind of pursuit, which is known as “hacking back.” Only a few government agencies, like the FBI, have the authority to hunt down suspected hackers in this way. Supporters of the bill, which was recently introduced in the US Congress, say the FBI and other government agencies are already overwhelmed by an onslaught of cyberattacks, including “ransomware” that has paralyzed computer systems in cities like Atlanta and Baltimore and massive data thefts at large companies like the Marriott hotel chain. In theory, giving businesses and individuals the right to do their own hunting would support the agencies' efforts. The link for this article located at MIT Technology Review is no longer available. . Examining the proposed Active Cyber Defense Certainty Act and its implications for cybersecurity and legislation.. Active Cyber Defense Certainty Act,Cybersecurity Risks,Hacking Back Implications. . Brittany Day
Security vendor Mandiant's 60-page report on Chinese cyberespionage, which offers proof that it is coming from a Chinese military unit housed in a building in the Pudong district of Shanghai, adds new fuel to two hotly debated cybersecurity questions.. First, does this mean the quest for 100% certainty in "attribution" of intrusions has been achieved? And second, does that mean the U.S. is justified in taking what government officials like to call "active defense" measures -- what most others call "retaliation" or "offense"? The link for this article located at CSO Online is no longer available. . The recent analysis by FireEye associates the Chinese armed forces with cyber surveillance, raising concerns about the accuracy of attributions and the efficacy of countermeasures in place.. Chinese Military,Cyberespionage,Cybersecurity Analysis,Mandiant Report. . LinuxSecurity.com Team
Security company Symbiot is about to launch a product that can hit back at hackers and DDoS attacks by lashing out with its own arsenal of tricks, but experts say it may just be a bit too trigger-happy. Symbiot, a Texas-based security firm, is preparing to launch a corporate defence system at the end of March that can fight back against distributed denial-of-service (DDoS) and hacker attacks by launching a counter-strike. . . .. Security company Symbiot is about to launch a product that can hit back at hackers and DDoS attacks by lashing out with its own arsenal of tricks, but experts say it may just be a bit too trigger-happy Symbiot, a Texas-based security firm, is preparing to launch a corporate defence system at the end of March that can fight back against distributed denial-of-service (DDoS) and hacker attacks by launching a counter-strike. In advance of the product launch, Symbiot's president, Mike Erwin, and its chief scientist, Paco Nathan, have outlined a set of "rules of engagement for information warfare", which they say should be part of corporate security policy to help companies determine their exact response to an incoming attack. "Until today, security solutions have been totally passive in nature. Merely erecting defensive walls around the perimeter of an enterprise network is not an adequate deterrent," said Erwin, who argues that to have a complete defence in place, offensive tactics must be employed. The company said it bases its theory on the military doctrine of "necessity and proportionality", which means the response to an attack is proportionate to the attack's ferocity. According to the company, a response could range from "profiling and blacklisting upstream providers" or it could be escalated to launch a "distributed denial of service counter-strike". Security experts expressed alarm at the company's plans. Graham Titterington, principal analyst at Ovum, said "such a counterattack would not be regarded as self-defence and would therefore be an attack. It would be illegal in thosejurisdictions where an anti-hacking law is in place." He added that because many hacking and DDoS attacks are launched from hijacked computers, the system would be unlikely to find its real target: "Attacks are often launched from a site that has been hijacked, making it an unwitting and innocent -- although possibly slightly negligent -- party." Richard Starnes, director of incident response at Cable and Wireless Managed Security Services, said he would not employ an "active defence technique" because there are legal and ethical issues involved. Also, he would not be happy about any product "specifically designed to launch attacks" being put into commercial production. Starnes said it would be easy to hit the wrong target and even if it was the right target, there could be collateral damage: "You may be taking out grandma's computer in Birmingham that has got a 100-year-old cookie recipe that has not been backed up. The attack could also knock over a Point of Presence (PoP), so you are not only attacking the target, but also the feeds before them -- this means taking out ISPs, businesses and home users." Jay Heiser, chief analyst at IT risk management company TruSecure, said that he expects the product to have "emotional appeal" to companies that have been targets, but "that is a very bad criterion for choosing risk-reduction measures." The link for this article located at ZDNet is no longer available. . Security company Symbiot is about to launch a product that can hitback at hackers and DDoS attacks b. security, company, symbiot, about, launch, product, hackers, attacks. . Anthony Pell
Active Countermeasures models the human body's immune reaction to invasion by microbes. It runs a periodic vulnerability analysis based on the latest advisories from security monitoring organizations such as CERT, prioritizes the threats, scans the network for vulnerable machines, then automatically deploys a payload of prevention. . . .. Active Countermeasures models the human body's immune reaction to invasion by microbes. It runs a periodic vulnerability analysis based on the latest advisories from security monitoring organizations such as CERT, prioritizes the threats, scans the network for vulnerable machines, then automatically deploys a payload of prevention. "We'll use the same opening the hacker used to get [malignant] code onto the machine," said HP Labs' distinguished technologist Joe Pato. Through that opening, a sort of vaccination in the form of a payload of code to deal with the threat is delivered. The countermeasures in the payload are determined by policies pre-set by the organization, and could include everything from popping up an alert on the threatened machine to automatically quarantining it from the network. The link for this article located at Enterprise Linux IT is no longer available. . Adaptive Defenses mimic biological reactions to combat cyber risks. Uncover the mechanics behind this groundbreaking strategy.. Network Security Strategies, Threat Prevention Techniques, Vulnerability Management, Active Defense Systems. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.