Monday, 17 June 2013

Facebook, Microsoft Join Google in Government Transparency Request

Despite denying any involvement and knowledge in the NSA's dubious PRISM surveillance program, tech giants aren't staying quiet about the need to shine public light on the number of secret national security requests they receive from the government. Facebook and Microsoft — two major companies implicated in the PRISM leak — have today joined Google in requesting increased transparency in government requests for user data.
Of course, PRISM is just the tip of the iceberg; Google, Microsoft, Facebook, and other major web service providers routinely receive requests from government agencies, which use "national security letters" to obtain data on users. These requests bind the targeted companies from informing users that their data has been passed on to the government or informing them that they are the target of an investigation.
As Reuters reports, a Microsoft spokesperson said that "permitting greater transparency on the aggregate volume and scope of national security requests, including FISA (Foreign Intelligence Surveillance Act) orders, would help the community understand and debate these important issues." Microsoft defended its disclosures to date, stating that "our recent report went as far as we could legally could and the government should take action to allow companies to provide additional transparency."
Facebook lumps the US government in with an ignominious bunch
Echoing Microsoft and Google, Facebook also chimed in on the secretive nature of US surveillance. As AllThingsD reports, Facebook general counsel Ted Ullyot said today that "we strongly encourage all governments to be much more transparent about all programs aimed at keeping the public safe. In the past, we have questioned the value of releasing a transparency report that, because of exactly these types of government restrictions on disclosure, is necessarily incomplete and therefor potentially misleading to users." Ullyot said that Facebook would "welcome the opportunity" to release a government-sanctioned transparency report. "We urge the United States government to help make that possible by allowing companies to include information about the size and scope of national security requests we receive, and look forward to publishing a report that includes that information," Ullyot said.

Why Israel is Losing the Internet War

Israel is losing the internet war for chiefly the same reason that France and Poland fell early in World War II. Israel is fighting a new war using old methods. The end results are predictable and devastating.
The first alarm bells should have gone off in the mid 90's. What struck me at that time was the number  of Neo-Nazi websites that sprung up like weeds. It was not until a few years later that the ADL was offering filtering software. By then the battle had been lost; the damage had not yet been fully appreciated.
In 1999, Hollywood was having conniptions that Napster's file sharing software was robbing them of royalties. What was ignored was that, simultaneously, regurgitated Nazi propaganda was being remastered and traded as well.
By 2000, Israel should have acted, but it didn't. With the ease of purchasing domains, anyone with an anti-Israel bias could open up a site. Cross-linking got them a high presence on Google. It wasn't until Jew Watch -- a vicious anti-Semitic site -- punched a number one rating for searches of the word, "jew" ("Joseph Turow and Lokman Tsui wrote in 2008 that the Wikipedia page [Jew Watch] on Jews had become the number one result for the search word "Jew".") that a realization of how far things had deteriorated had finally set in.
But again, old methods were tried to fight the flood. Hate crime laws were applied to shut down sites, and punish their authors, such as happened with Ernst Zündel and his Zündelsite. There were requests to delist Jew Watch from Google. A Remove Jew Watch Campaign was started.
Apart from the fact that such methods are authoritarian, and only added to the criticism of Jews -- "What were the Jews trying to hide?" -- they did not work. The Canadian-resident Zündel merely transferred ownership of his site to his American wife -- and it is on an American server to this day, putting it outside the jurisdiction of Canadian hate crimes laws. Zündel would be deported to Germany under suspiciously political circumstances, which gave a foolish holocaust-denying clown the opportunity to redefine himself as a champion of free speech. Worst of all, Muslims used these very same hate crime laws to prevent criticism of Islam. All of this response was old school; and all of it backfired.
Jew Watch is still up and running; and still running rather high on Google, even though far worse anti-Semitic sites have sprung up.
So what were the mistakes?
A) Israel and the World Jewish Community sought to suppress anti-Semitism. The internet does not allow suppression. Getting court orders to shut down a site takes time. In the interim, a hundred new sites can spring up, some no more than mere mirror replications of the old site being suppressed. The Jewish response was that of an old world East European autocracy trying to shut down dissident printing presses. Given the history of the Jews, many of whom came from Eastern Europe, and some of whom ran those dissident presses, they should have known better. You can't stop a rebellion shutting down one press at a time.
B) Israel and the World Jewish Community did not fully appreciate the fluid and transnational nature of the internet. While Europe, with its hate crime laws, could be persuaded to shut down anti-Semitic websites, there is nothing stopping a European from opening up his website on an American server, under American First Amendment protections. RadioIslam.org is a notorious website set up by a former Moroccan, with connections to a Swedish Nazi, both of whom have spent time in Swedish jails for hate crimes. However, the website is hosted in the USA, and a WHOIS search shows it to be administered under a semi-anonymous cover with a Pennsylvania address. The Europeans can't touch the site.
C) YouTube is a game changer. Anybody with a camera can photograph some IDF abuse -- and it does happen -- and have it up on YouTube in a matter of minutes. Of course, all balancing context and information will be edited out.
D) Finally, all too often Israeli apologists tried to defend Israel by logic and appeals to reason. Dr. Martin Sherman of Tel Aviv might give an hour-long well-reasoned defense of a Jewish state, but it is meaningless on the internet, which has the attention span of a Sesame Street commercial for the letter Z. Jews might appreciate Talmudic logic, but Generation Y, thanks to our educational system, is technically brilliant, but functionally illiterate. Any appeal above the level of a lurid comic will be ignored. If it can't be reduced to a tweet, forget it.
Authoritarian media control will not work in an age where websites sprout like dandelions. Enforcing hate laws will not work when websites can move offshore. Reasoned discussion will not work when our education systems have dumbed down the constituencies.
Israel must fight back with a counter-blitz.
A) Hundreds of videos of Muslim outrages should be distributed daily. Fortunately, these are not hard to find. Many times, the Muslims upload the offensive boastful videos themselves. Millions of emails should be sent out daily linking to these videos.
B) Be brutal! This horrific photo [be warned] of a female genital mutilation procedure done to an Egyptian girl should be sent to every female in the Western world. The email headline should read: This is What Defending Islam Means. This could be done in a matter of days. Be sure to point out that it does occur in Gaza and the contested areas. Point out that this crime is rare outside proximity to Islam. Make no apologies for the email. Half the pro-Palestinian campus activity will cease within a month.
C) Hammer home the total lack of freedom, especially religious freedom in Islam. Every outrage must be mass mailed to millions of people.
D) Get rid of the hasbara activists, who are often quite dull, and annoying, even to supporters of Israel. Ten million emails sent out every day about Islamic outrages will do more good than any number of awkward hasbara activists in chatrooms fighting a propaganda war with tired slogans no one believes anymore.
E) Hire spammers to set up mailing campaigns. The West should be inundated daily with anti-Islam messages. The Arabists fight dirty. So should you. Assemble massive email lists, sorted by constituency Change servers to avoid blocking.
F) This is not about reason. The Jewish world abhors images as a foundation of logic, due to the Second Commandment. Forget that! You are trying to win the hearts of us Goyim. We need images, not the musings of Rashi. Graphic images! Lots of them! Daily! Hammer the point home! When the media screams foul, redouble the effort.
Finally, and this will be controversial: The ancient Israelites could not advance into the land until they dealt with the sin of Achan. Israel does tolerate some abusive settlers; and use some oppressive or prejudicial legal wranglings when dealing with Arabs, even Israeli Arabs. Until Israel deals with these issues, be assured the Arabists will make effective hay of Israel's sins to cover up Islam's far greater crimes. For the time being Israel must reign in violent settlers, and give the Arabs as much justice as is possible, if only to deprive the other side of ammunition in the propaganda war.
The first thing New York's Mayor Giuliani did when he started his war on crime was arrest crooked cops. Israel should do likewise.
Israel must change its tactics in the Internet War. Appeals to reason will not work with a generation which has be taught illiteracy. Israel must abandon its old methods, and fight hard and furious with the weapons of the internet. Images, videos, and cartoons.

Friday, 14 June 2013

An introduction of DDoS mitigation techniques focused on Cloud-based DDoS Mitigation solution, an approach implemented by many companies.

Despite their prevalence, DDoS (Distributed Denial of Service) attacks have been erroneously considered minor attacks by some parts of the security community due their “limited” duration. Victims of DDoS attacks are typically forced to interrupt their services for a few hours without any other observable damage.
Recent events, however, have demonstrated that the impact of DDoS attacks is much more than meets the eye. Not only can these attacks inflict huge economic losses, they can also have a serious impact on the reputation and image of the victimized company or organization.
Another worrying trend observed in recent DDoS attacks is that in addition to targeting web infrastructures, attackers are also trying to exploit flaws and improper configurations within the Domain Name System (DNS) infrastructures. Arbor Networks’ 2012 Worldwide Infrastructure Security Report indicated that 41% of respondents experienced DDoS attacks against their DNS infrastructure.
DDoS Mitigation Incapsula
Moreover, the targets of a DDoS attack do not fit into a specific category. Providers of online banking, payment services, email services and just about every other type of web service provider are prime candidates.
Similarly, there is no typical profile of an attacker – cyber criminals, hacktivists and state-sponsored hackers all use similar tactics to hit a large list of targets.
Principal Categories of DDoS Attacks
The security community classifies DDoS attacks as follows:
  • Volume Based Attacks –The attacker tries to saturate the bandwidth of the target’s website by flooding it with a huge quantity of data. This category includes ICMP floods, UDP floods and other spoofed-packet floods. This type of attack is very common and simple to execute using the vast quantity of free tools available on the Internet, and, as such, is very popular in the hacktivist underground. The magnitude of Volume Based Attacks is measured in bits per second (Bps).
  • Protocol Attacks –The attacker’s goal is to saturate the target’s server resources or those of intermediate communication equipment (e.g., Load balancers) by exploiting network protocol flaws. This category includes SYN floods, Ping of Death, fragmented packet attacks, Smurf DDoS and more. The magnitude of Protocol Attacks is measured in Packets per second.
  • Application Layer (Layer 7) Attacks – Designed to exhaust the resource limits of Web services, application layer attacks target specific web applications, flooding them with a huge quantity of HTTP requests that saturate a target’s resources. Application layer attacks are hard to detect because they don’t necessarily involve large volumes of traffic and require fewer network connections than other types of DDoS techniques. Examples of application layer DDoS attacks include Slowloris, as well as DDoS attacks that target Apache, Windows, or OpenBSD vulnerabilities. The magnitude of application layer attacks is measured in Requests per second.
DDoS Mitigation Solutions – Traditional vs. Cloud-Based
The increase in the magnitude and complexity of DDoS attacks highlights the need for organizations to adopt proper countermeasures and mitigation techniques. Naturally, time is of the essence when it comes to DDoS protection. Prompt DDoS detection is a critical phase of the mitigation process – the faster security systems can detect a potential threat, the better the chance of minimizing damage and even neutralizing the threat.
Firms that provide solutions for DDoS mitigation follow various approaches to protect their customers. The first step in protecting a company’s web infrastructure against a DDoS attack is to identify normal conditions for network traffic. This definition of normal “traffic patterns” is necessary baseline for threat detection and alerting. The majority of commercial solutions provides threshold-based alerting mechanisms that trigger alerts based on the collection of meaningful information from the logs.
Another common detection approach is known as “Layered Filtering,”, dedicated appliances and software detect and mitigates different types of attacks in both the network and application layers. Defense mechanisms which analyze traffic in layers try to detect harmful traffic and apply filters to block the threats at the specific level. Many companies also adopt open source software to limit the incoming number of connections and traffic dimensions.
DDoS Mistigation SolutionIncapsula
Traditional DDoS mitigation solutions oversize the network bandwidth and adopt complex hardware such as firewalls and load balancers. Many experts consider this approach to be unnecessarily costly and in many cases ineffective. For this reason, many companies have chosen to adopt a cloud-based approach to DDoS protection with direct management of DNS services, enabling them to optimize their response to malicious events. Another advantage of a cloud-based approach is the reduction of investment in equipment and infrastructure (capex) as well as the reduced cost of managing and maintaining typical hardware solutions (opex).
Key Criteria for Evaluating DDoS Mitigation Solutions
Choosing a DDoS mitigation solution is far from a simple task, given the numerous alternatives and choices, such as hardware versus software, appliance versus cloud-based solutions, etc.  To simplify your decision process, the following checklist includes the most important features/criteria to evaluate before acquiring a new product:
  • Capacity of solution in term of protocols supported, analysis path implemented and granularity offered for traffic inspection.
  • Support for traffic profiling. Companies offering a variety of services may wish to define a different policy for each service. Normal traffic patterns for various services could be substantially different. For example, analyzing a banking website the traffic related to the users that simply visit the portal must be differentiated from the one related to banking customers that access to home banking functions.
  • Product flexibility – the possibility to create ad hoc policies and patterns starting from well-known configurations.
  • Product scalability – the product should be able to evolve and scale with the changing needs of the buyer.
  • Availability of built-in hardware redundancy features
  • Availability of an efficient reporting/alerting system. Various solutions provide very different levels of reports and alerts – these features should be evaluated with care.
  • Reliability – DDoS is a dynamic threat that morphs over time. Be sure to choose a solution provider that is able to provide continuous updates and prompt support for its products.
  • Bidirectional traffic monitoring – It is important to control both inbound and outbound traffic to prevent the abuse of network resources by attackers.
  • Product reputation and customer references. This is a crucial aspect that must take into account the features of product and maintenance services.
How does the cloud based DDoS mitigation approach work?
As noted earlier, one of most popular mitigation approaches is cloud-based DDoS mitigation. Such solutions are offered by Incapsula, Prolexic and Verisign, among others.  Successful mitigation depends on the ability to monitor and analyze traffic patterns in real time.  When a DDoS attack is detected by monitoring systems, the malicious traffic is redirected from the targeted website to a mitigation architecture through the cloud. Inbound malicious traffic is sent to the nearest scrubbing center, where the mitigation solution applies DDoS filtering and routing techniques to reduce DDoS traffic interference. The clean traffic is then routed back to the customer’s network. Accordingly, the capacity of the scrubbing centers and the filtering methods used are crucial for the provisioning of an efficient DDoS mitigation service.
To get an industry expert’s take on these topics, I contacted Incapsula, one of the leading providers of DDoS mitigation services. Incapsula offers Web Security, DDoS Protection, Failover & Load Balancing on a Global CDN. The company was spun out of and is financially backed by Imperva [IMPV], a leading provider of data security solutions. Here are excerpts from my interview with Incapsula’s  CEO, Gur Shatz.
What are the key criteria for a successful DDoS mitigation service?
“Well, there are various factors that contribute to a successful DDoS mitigation solution, such as:
  • Network size: You need a mitigation service that can handle the largest possible attack that could come your way. Since attacks are becoming larger at a disturbing rate, anything below 250Gbps of network capacity just isn’t enough.
  • Automatic detection: There are many ways to launch a DDoS attack, and sometimes the nature of the attack rather than its size is what makes mitigation so hard. Take, for example, hit and run attacks which are short bursts of traffic in random intervals over a long period of time. A manual mitigation solution that requires users to turn it on and off on every burst will throw the IT team into complete havoc. Some solutions, like Incapsula, offer automatic DDoS mitigation and take full responsibility for both detection and mitigation of the attack.
  • Transparent mitigation: DDoS is about degradation of service. While this can be complete denial of service, it can also be disruptions. If your DDoS mitigation service introduces a large rate of false positives or degrades the normal user experience in any way, the DDoS attack is actually achieving its goal – even if your service is still up and running. Unless your mitigation service can offer zero disruption to the normal user experience, you will not be able to withstand lengthy attacks without damaging business performance.
  • Time and complexity to onboard: A key factor in a DDoS service is the time it takes to on-board the service. There are various techniques and setups – the more complex ones require on‑premise devices and configuration, while the faster ones require only a simple DNS change. When you are under fire, you’ll appreciate having chosen a solution that can shield your network from that attack with minimal time and effort.
  • Support: A 24×7 team of experts is an essential part of a reliable DDoS mitigation service. Being under a DDoS attack is one of the most frustrating situations for any IT manager. You have practically no visibility into what is happening, there is nothing you can do internally and your entire service is down. You need an expert by your side who can help you understand what is going on during the attack and get you through it as painlessly as possible.”
Based on the observation of DDoS attacks against your clients during the last few months, what are the changes/trends that you are seeing with respect to attack methods?
“The principal trends that we are observing are:
  • Larger and larger network attacks. These large-scale attacks are often using SYN flood and DNS amplifications as their tool of choice.
  • Hit and Run attacks. These are smaller scale application layer attacks that don’t last very long, but occur every few days.
This information might be biased, because as a cloud provider, we are well suited for handling large network attacks. Since our users typically use our “always on” automatic detection service, it is reasonable to assume that users with hit and run problems tend to reach us more than users of other solutions.”
What are the strong points of your Cloud-based solution?
“I believe that our true strengths lie in a number of aspects of our service:
  • We offer a cloud based service that can be activated without any additional hardware, software or other integration requirements. Adding a website to Incapsula is done through a simple DNS change which allows us to offer our services to practically anyone regardless of company size, IT manpower or expertise.
  • A large network of more than 300Gbps that can handle practically any attack out there.
  • Transparent and automatic mitigation of attacks with no negative (and in most cases positive) effect on legitimate users’ experience.
  • Having a built-in CDN and Web Application Firewall allow our customers to always be online and automatically mitigate attacks while improving overall user experience and overall security.”
Whatever solution you choose, you must always consider the trade-off between costs and benefits. To meet business goals, every company is increasing its exposure on the Internet and, in parallel, enlarging the potential surface of attack. At the same time, downtime is no longer acceptable from a business standpoint for the majority of these companies.

IT Governance


IT Governance

Corporate Governance

Corporate governance refers to the way a corporation is governed. Corporate governance deals with determining ways to take effective strategic decisions and further refers to the set of systems, principles and processes by which a company is governed. They provide the guidelines as to how the company can be directed or controlled such that it can fulfil its goals and objectives in a manner that adds to the value of the company and is also beneficial for all stakeholders in the long term. Stakeholders in this case would include everyone ranging from the board of directors, management, shareholders to customers, employees and society. The management of the company hence assumes the role of a trustee for all the others.

IT Governance or Information Technology Governance

Information technology governance, however, is a subset discipline of Corporate Governance. Although it is sometimes mistaken as a field of study on its own, IT Governance is actually a part of the overall Corporate Governance Strategy of an organization. In simple words IT Governance is putting structure around how organizations align IT strategy with business strategy, ensuring that companies stay on track to achieve their strategies and goals, and implementing good ways to measure IT’s performance. It makes sure that all stakeholders’ interests are taken into account and that processes provide measurable results. A IT governance framework should answer some key questions, such as how the IT department is functioning overall, what key metrics management needs and what return IT is giving back to the business from the investment it’s making.
The primary goals of IT Governance are to assure that the investments in IT generate business value, and to mitigate the risks that are associated with IT. This can be done by implementing an organizational structure with well-defined roles for the responsibility of information, business processes, applications and infrastructure.
Organizations or business needs a structure or framework to ensure that the IT function is able to sustain the organization’s strategies and objectives. The framework and level we need depends on the size, industry or applicable laws or regulations. In general, the larger and more regulated the organization, the more detailed the IT governance structure should be.

IT Governance Framework

It doesn’t make sense to reinvent the wheel by starting from scratch. Start with a IT governance framework; there are many to choose from, but using at least one means everything has already been organized by industry experts.
A IT governance framework includes three elements:
  • Governance principles – the principles by which all IT initiatives will be governed
  • Governance structure – the roles and responsibilities of the major stakeholders in the IT governance decision-making process, including committees and organizational elements at the branch level
  • Governance process – the various stages required to review, assess and approve or reject new IT initiatives
Implementing good IT governance requires a framework.

COBIT

This framework Control Objectives for Information and related Technologies (COBIT) was developed in 1996, from the Information Systems Audit and Control Association (ISACA), is probably the most popular. Basically, it’s a set of guidelines and supporting toolset for IT governance that is accepted worldwide. It’s used by auditors and companies as a way to integrate technology to implement controls and meet specific business objectives. COBIT 5 is the only business framework for the governance and management of enterprise IT. This evolutionary version incorporates the latest thinking in enterprise governance and management techniques, and provides globally accepted principles, practices, analytical tools and models to help increase the trust in, and value from, information systems. COBIT 5 builds and expands on COBIT 4.1 by integrating other major frameworks, standards and resources, including ISACA’s Val IT and Risk IT, Information Technology Infrastructure Library (ITIL) and related standards from the International Organization for Standardization (ISO).

ITIL

The Information Technology Infrastructure Library(ITIL) from the government of the United Kingdom runs a close second to CoBIT. The Information Technology Infrastructure Library (ITIL) is a set of practices for IT service management (ITSM) that focuses on aligning IT services with the needs of business. In its current form (known as ITIL 2011 edition), ITIL is published in a series of five core publications, each of which covers an ITSM lifecycle stage. ITIL underpins ISO/IEC 20000 (previously BS15000), the International Service Management Standard for IT service management, although differences between the two frameworks do exist. ITIL describes processes, procedures, tasks and checklists that are not organization-specific, used by an organization for establishing integration with the organization's strategy, delivering value and maintaining a minimum level of competency. It allows the organization to establish a baseline from which it can plan, implement, and measure. It is used to demonstrate compliance and to measure improvement.

Wednesday, 12 June 2013

Unacceptable if US is found violating Indian privacy laws: Govt

http://kaw.stb.s-msn.com/i/AB/3EA7DE6E596BBD917189C16D618A0.jpg"If it is discovered that Indian laws relating to privacy of information of ordinary Indian citizens have been violated we would find it unacceptable," external affairs ministry spokesperson Syed Akbaruddin said at a media briefing
 New Delhi: India said it would be "unacceptable" if it is discovered that Indian laws on privacy have been violated by the surveillance launched on web users worldwide by the US National Security Agency (NSA).
"If it is discovered that Indian laws relating to privacy of information of ordinary Indian citizens have been violated we would find it unacceptable," external affairs ministry spokesperson Syed Akbaruddin said at a media briefing yesterday.
His reaction came following revelations that the National Security Agency (NSA) has been spying on emails, social network activity, listening in on internet calls around the world since 2007.
A former CIA agent revealed to the Washington Post and the Guardian newspapers that the US agency has been using tech giants Microsoft, Google, Apple, Yahoo, Facebook, Skype and YouTube to spy on private information of users around the world.
The programme, codenamed 'PRISM' has been in operation since 2007. The programme is aimed to monitor foreign communications that take place on US servers.
Akbaruddin also said that India is 'concerned and surprised' by revelations that the US intelligence agency may be tapping information secretly. He said that India and the US have a cyber-security dialogue that is helmed by the National Security Advisers from both sides.
'We intend to seek information and details during the consultations between the interlocutors', he said, and added that it is an evolving situation and India would see how the matter unfolds rather than jump to conclusions.
Former CIA technical worker Edward Snowden has been identified by the Guardian newspaper as the person who leaked information about US surveillance programmes.