Τετάρτη 28 Ιανουαρίου 2015

ENISA Threat Landscape 2014


ENISA published the third yearly report in sequence Threat Landscape 2014 (ETL 2014), consolidating and analyzing the top cyber threats and the evolution, encountered in 2014. ENISA Threat Landscape 2014, an activity contributing towards achieving the objectives formulated in the Cyber Security Strategy for the EU, stresses the importance of threat analysis and the identification of emerging trends in cyber security.

No previous threat landscape document published by ENISA has shown such a wide range of change as the one of the year 2014. We were able to see impressive changes in top threats, increased complexity of attacks, successful internationally coordinated operations of law enforcement and security vendors, but also successful attacks on vital security functions of the internet.
Many of the changes in the top threats can be attributed to successful law enforcement operations and mobilization of the cyber-security community:

  • The take down of GameOver Zeus botnet has almost immediately stopped infection campaigns and Command and Control communication with infected machines.
  • Last year’s arrest of the developers of Blackhole has shown its effect in 2014 when use of the exploit kit has been massively reduced.
  • NTP-based reflection within DDoS attacks are declining as a result of a reduction of infected servers. This in turn was due to awareness raising efforts within the security community.
  • SQL injection, one of the main tools used to compromise web sites, is on the decline due to a broader understanding of the issue in the web development community.
  • Taking off-line Silk Road 2 and another 400 hidden services in the dark net has created a shock in TOR community, both at the attackers and TOR users ends.
But there is a dark side of the threat landscape of 2014:

  • SSL and TLS, the core security protocols of the internet have been under massive stress, after a number of incidents have unveiled significant flaws in their implementation.
  • 2014 can be called the year of data breach. The massive data breaches that have been identified demonstrate how effectively cyber threat agents abuse security weaknesses of businesses and governments.
  • A vulnerability found in the BASH shell may have a long term impact on a large number of components using older versions, often implemented as embedded software.
  • Privacy violations, revealed through media reports on surveillance practices have weakened the trust of users in the internet and e-services in general.
  • Increased sophistication and advances in targeted campaigns have demonstrated new qualities of attacks, thus increasing efficiency and evasion through security defences.
In the ETL 2014, details of these developments are consolidated by means of top cyber threats and emerging threat trends in various technological and application areas. References to over 400 relevant sources on threats will help decision makers, security experts and interested individuals to navigate through the threat landscape.

Πέμπτη 18 Δεκεμβρίου 2014

ENISA CERT training

ENISA has launched a new section on its website introducing the ENISA CERT training program. In the new section, you can find all the publicly available training resources and the training courses currently provided by ENISA.
The material has been categorized into 4 main topics:
  • Technical,
  • Operational,
  • Setting up a CERT, and
  • Legal and cooperation.
Additionally, various tools for hands-on training (such as Virtual Machines) are provided. In 2014 training scenarios were added covering various topics in the area of artifact handling and analysis. Artifact analysis involves receiving information about artifacts that are used in attacks, reconnaissance, and other unauthorized or disruptive activities. The created course covers the topics of building an artifact handling and analysis environment, the fundamentals for artifact analysis, as well as advanced artifact analysis and a common framework for artifact analysis activities.

Visit the new page and material here.

Topics

Technical
  • Building artifact handling and analysis environment
  • Processing and storing artifacts
  • Artifact analysis fundamentals
  • Advanced artifact handling
  • Developing Countermeasures
  • Common framework for artifact analysis activities
  • Identification and handling of electronic evidence
  • Digital forensics
  • Mobile threats indident handling
  • Proactive incident detection
  • Automation in incident handling
  • Network forensics
  • Honeypots
  • Vulnerability handling
  • Presenting, correlating and filtering various feeds
Operational
  • Incident handling during an attack on Critical Information Infrastructure
  • Advanced Persistent Threat incident handling
  • Social networks used as an attack vector for targeted attacks
  • Writing Security Advisories
  • Cost of ICT incident
  • Incident handling in live role playing
  • Incident handling in the cloud
  • Large scale incident handling
Setting Up a CERT
  • Triage & Basic Incident Handling
  • Incident handling procedure testing
  • Recruitment of CERT staff
  • Developing CERT infrastructure
Legal and Cooperation
  • Establishing external contacts
  • Cooperation with law enforcement
  • Assessing and Testing Communication Channels with CERTs and all their stakeholders
  • Identifying and handling cyber-crime traces
  • Incident handling and cooperation during phishing campaign
  • Cooperation in the Area of Cybercrime
  • CERT participation in incident handling related to the Article 13a obligations
  • CERT participation in incident handling related to the Article 4 obligations

Τετάρτη 19 Νοεμβρίου 2014

ENISA Set to Establish a Framework for Cyber Security Competitions


Today the European Union Agency for Network and Information Security (ENISA) announced the planning of the 1st pan-European Cyber Security Competition in 2015. The competition is organised jointly in collaboration with experienced organisations from EU Member States for students.

The Organizing Committee of the 1st pan-European Cyber Security Challenge is composed of the following representatives: 
  • Norbert Pohlmann - Cyber Security Challenge Germany;
  • Joe Pichlmayr — Cyber Security Challenge Austria;
  • Andrei Avădănei —DefCamp Romania; 
  • Raúl Riesco- INTECO Spain;
  • Okonweze Austen — Cyber Security Challenge UK;
  • Bernhard Tellenbach — Swiss Cyber Storm;
  • Demosthenes Ikonomou- ENISA and
  • Rafael Tesoro-Carretero- EC DG CONNECT.
Cybersecurity competitions — the status in Europe

ENISA also publishes a new report analyzing the current situation concerning cybersecurity- challenge competitions in Europe. The experience gathered constitutes the basis for the development of the pan-European competition on cybersecurity.

The European Cyber Security Challenge Competition 2015 aims to be the result of a public–private partnership comprised of capable players, aiming at improving the ICT educational approach to Europe’s digital citizens.

The report provides a general overview of existing cybersecurity- challenge competitions in Member States and outlines a roadmap for a future pan-European cyber-challenge competitions. The first part presents the experience of five countries while the second comprises of a short ‘how to’ guide containing the steps in organizing a challenge. The third part gives details on concrete developments concerning a pan-European challenge. The last part of the report contains several recommendations that should be taken into account. Graphics providing additional content are provided in the annex.

Πέμπτη 30 Οκτωβρίου 2014

Biggest ever cyber security exercise in Europe


More than 200 organisations and 400 cyber-security professionals from 29 European countries are testing their readiness to counter cyber-attacks in a day-long simulation, organised by the European Union Agency for Network and Information Security (ENISA).
Biggest ever cyber security exercise in Europe today
In Cyber Europe 2014 experts from the public and private sectors including cyber security agencies, national Computer Emergency Response Teams, ministries, telecoms companies, energy companies, financial institutions and internet service providers are testing their procedures and capabilities against in a life-like, large-scale cyber-security scenario.

#CyberEurope2014 is the largest and most complex such exercise organised in Europe. More than 2000 separate cyber-incidents will be dealt with, including denial of service attacks to online services, intelligence and media reports on cyber-attack operations, website defacements (attacks that change a website's appearance), ex-filtration of sensitive information, attacks on critical infrastructure such as energy or telecoms networks and the testing of EU cooperation and escalation procedures. This is a distributed exercise, involving several exercise centres across Europe, which is coordinated by a central exercise control center.
European Commission Vice-President Neelie Kroes said: "The sophistication and volume of cyber-attacks are increasing every day. They cannot be countered if individual states work alone or just a handful of them act together. I'm pleased that EU and EFTA Member States are working with the EU institutions with ENISA bringing them together. Only this kind of common effort will help keep today’s economy and society protected."

The Executive Director of ENISA, Professor Udo Helmbrecht, commented: “Five years ago there were no procedures to drive cooperation during a cyber-crisis between EU Member States. Today we have the procedures in place collectively to mitigate a cyber-crisis on European level. The outcome of today’s exercise will tell us where we stand and identify the next steps to take in order to keep improving.”

The #CyberEurope2014 exercise will, among others, test procedures to share operational information on cyber-crisis in Europe; enhance national capabilities to tackle cyber crises; explore the effect of multiple and parallel information exchanges between private-public, private-private at national and international level. The exercise also tests out the EU-Standard Operational Procedures (EU-SOPs), a set of guidelines to share operational information on cyber crisis.

Background

According to ENISA’s Threat Landscape report (2013), threat agents have increased the sophistication of their attacks and their tools. It has become clear that maturity in cyber activities is not a matter of a handful of countries. Rather, multiple countries have developed capabilities that can be used to infiltrate all kinds of targets, governmental and private in order to achieve their objectives.
In 2013, global web web-based attacks increased by almost a quarter and the total number of data breaches was 61% higher than 2012. Each of the eight top data breaches resulted in the loss of tens of millions of data records while 552 million identities were exposed. According to industry estimates cyber-crime and espionage accounted for between $300bn and $1tn in annual global losses in 2013.

The exercise

This exercise simulates large-scale crises related to critical information infrastructures. Experts from ENISA will issue a report with key findings after the exercise ends.
#CyberEurope2014 is a bi-annual, large scale cyber security exercise. It is organised every two years by ENISA, and this year counts 29 European countries (26 EU and 3 from EFTA) plus EU Institutions. It takes place in 3 phases throughout the year: technical, which involves the incident detection, investigation, mitigation and information exchanges (completed in April); operational/tactical, dealing with alerting, crisis assessment, cooperation, coordination, tactical analysis, advice and information exchanges at operational level (today) and early 2015; strategic, which examines decision making, political impact and public affairs. This exercise will not affect critical information infrastructures, systems, or services.
In the Cyber security Strategy for the EU and proposed Directive for a high common level of network and information security (NIS), the European Commission calls for the development of national contingency plans and regular exercises, testing large-scale networks’ security incident response and disaster recovery. ENISA’s new mandate also highlights the importance of cyber-security preparedness exercises in enhancing trust and confidence in online services across Europe. The draft EU-SOPs have been tested over the last three years, including during CE2012.