• CybersecurityStrengthening U.S. cybersecurity capabilities by bolstering cyber defense, deterrence

    Top officials from the Defense Department and the intelligence community told a Senate panel that defense and deterrence are two of the highest priorities for bolstering the nation’s cybersecurity capabilities. Director of National Intelligence James R. Clapper said that for the third year in a row, cyberthreats headed the list of threats reported in the annual National Intelligence Worldwide Threat Assessment. “Although we must be prepared for a large Armageddon-scale strike that would debilitate the entire U.S. infrastructure, that is not … the most likely scenario,” Clapper said. Rather, the primary concern is low- to moderate-level cyberattacks from a growing range of sources that will continue and probably expand, adding that in the future he expects to see more cyber operations that manipulate electronic information to compromise its integrity, as opposed to deleting or disrupting access to it.

  • CybersecurityRussia-based hackers tried to break into Hillary Clinton's private server

    Russian hackers, on five separate occasions, tried to break into Hillary Clinton’s server. The malicious e-mails, disguised as New York City parking tickets, were contained in the latest batch of records released by the State Department. There is no indication that these attempts were successful or that the suspicious zip files were opened by Clinton, but her personal e-mail address was a tightly-held secret and the hacking attempts raise the question of whether she was specifically targeted.

  • CybersecurityCybersecurity company licenses ORNL’s Data Diode

    Data Diode, developed by ORNL’s researchers, uses a defense-in-depth computer network strategy to create an environment in which an organization’s approved users can work freely inside an enclave of protected data but restricts file transfers outside the network. Lock Data Solutions has licensed a technology from ORNL. The technology is designed to protect a company’s data from internal and external threats.

  • EncryptionSupposedly encrypted national identifying numbers easily decrypted

    Studies raise questions about the use of national identifying numbers by showing that Resident Registration Numbers (RRN) used in South Korea can be decrypted to reveal a host of personal information. A team of researchers in two experiments was able to decrypt more than 23,000 RRNs using both computation and logical reasoning. The findings suggest that, while such identifiers are encrypted to protect privacy, they remain vulnerable to attack and must be designed to avoid such weaknesses.

  • CybersecurityDHS S&T awards $14 million for developing defenses against DDoS attacks

    Typical DDoS attacks are used to render key resources unavailable, such as disrupting an organization’s Web site and temporarily block a consumer’s ability to access the site. A more strategic attack may render a key resource inaccessible during a critical period. The Department of Homeland Security (DHS) Science and Technology Directorate (S&T) the other day announced the award of eight contracts totaling $14 million for research on technologies to defend against DDoS attacks.

  • Voice recognitionAutomated voice imitation can defeat voice-recognition security

    Voice biometrics is based on the assumption that each person has a unique voice that depends not only on his or her physiological features of vocal cords but also on his or her entire body shape, and on the way sound is formed and articulated. Researchers have found that automated and human verification for voice-based user authentication systems are vulnerable to voice impersonation attacks. Using an off-the-shelf voice-morphing tool, the researchers developed a voice impersonation attack to attempt to penetrate automated and human verification systems.

  • view counter
  • CybersecuritySearching for malware hidden in shortened URLs on Twitter

    Cyber-criminals are taking advantage of real-world events with high volumes of traffic on Twitter in order to post links to websites which contain malware. To combat the threat, computer scientists have created an intelligent system to identify malicious links disguised in shortened URLs on Twitter. They will test the system in the European Football Championships next summer.

  • CybersecurityProtecting Navy ships from cyberattacks

    For most people, the term “cyber security” calls to mind stories of data theft like the recent hacks of the OPM database, or network spying like the 2012 breach of the Navy-Marine Corps Intranet. But in this networked world, hackers might also try to disable or take control of machines in our physical world — from large systems like electric power grids and industrial plants, to transportations assets like cars, trains, planes or even ships at sea.

  • CybersecurityDHS S&T awards UCSD $1.3million for cyber security research

    DHS S&T the other day awarded a contract to the University of California San Diego (UCSD) to create technology to defend against large and sophisticated Distributed Denial of Service (DDoS) attacks. The $1.3 million project, “Surveying Spoofing Susceptibility in Software Systems,” aims to measure and improve the use of source address validation (SAV) in the Internet. In many cases, an attacker can send Internet packets using a false source address. In other words, the attacker falsely reports the packets are coming from a company, organization, or government agency when in fact the packets are coming from the attacker.

  • CybersecurityA first: Anti-fraud system to use existing credit card readers

    From large-scale data breaches such as the 2013 Target case to local schemes that use skimming devices to steal data at the gas pump, credit card fraud is becoming commonplace. Because existing magnetic card readers use plain text to store confidential information, they are vulnerable to an untrusted card reader or skimming device. Analysts estimate that this vulnerability is adding up to $8 billion in incurred losses per year in the United States. For the first time, researchers have developed an inexpensive, secure method to prevent mass credit card fraud using existing magnetic card readers.

  • CybersecurityImproving cybersecurity, reducing online theft

    NIST the other day announced it will award nearly $3.7 million for three pilot projects designed to make online transactions more secure and privacy-enhancing for healthcare, government services, transportation, and the Internet of Things. The three recipients of the National Strategy for Trusted Identities in Cyberspace (NSTIC) grants will pilot solutions aimed at reducing tax refund theft, improving the security of medical information and providing secure online data storage.

  • CybersecurityClearance of employees who repeatedly fall for phishing scams should be revoked: Experts

    People are one vital component in the 3P security system (the others being process and product). Some of the people who handle sensitive government information also continue to fall for human engineering techniques like phishing. The question is: should the individuals who repeatedly fall for these scams have their security clearance revoked? Absolutely they should, maintains DHS chief security officer (CIS) Paul Beckman.

  • CybersecurityBeyond data theft: Next phase of cyber intrusions will include destruction, manipulation of data

    James Clapper, director of U.S. intelligence, and other senior intelligence officers, have warned Congress that the next phase of escalating online data theft will likely involve the manipulation of digital information. Clapper on Wednesday told lawmakers on the House Intelligence Committee that a “cyber Armageddon,” in which a digitally triggered damage to physical infrastructure results in a series of catastrophic events, is less likely than “cyber operations that will change or manipulate data.” Leaders of the U.S. intelligence community told lawmakers that the manipulation or destruction of data would undermine confidence in data stored on or accessible through U.S. networks, engendering an uncertainty which could jeopardize U.S. military situational awareness and undermine business activity.

  • CybersecuritySmart watches allow hackers to harvest users’ data

    They are the latest rage in jewelry and gadgetry, but like all computer devices, smart watches are vulnerable to hackers. Using a homegrown app on a Samsung Gear Live smart watch, researchers were able to guess what a user was typing through data “leaks” produced by the motion sensors on smart watches. The project, called Motion Leaks through Smartwatch Sensors, or MoLe, has privacy implications, as an app that is camouflaged as a pedometer, for example, could gather data from emails, search queries and other confidential documents.

  • CybersecuritySecuring and protecting the emerging Internet of Things

    The digital world once existed largely in non-material form. But with the rise of connected homes, smart grids and autonomous vehicles, the cyber and the physical are merging in new and exciting ways. These hybrid forms are often called cyber-physical systems (CPS), and are giving rise to a new Internet of Things. National Science Foundation and Intel Corporation team to improve the security and privacy of computing systems that interact with the physical world using a new cooperative research model.