Friday, March 2, 2012

The Tiger & The Elephant - The 21st Century Posture for Information Assurance

In Complete Darkness - The Genesis of a New Vision:
In just one night, 50 million people sitting in the dark dramatically changed the future of computer security for the 21st century. On August 14, 2003 America witnessed the largest power outage in its history. In less than two minutes, cities from New York to Cleveland, Detroit to Toronto had been disconnected from their electrical grids and plunged into sudden blackness.
After four months of sifting through factual and anecdotal evidence, findings would show that improperly pruned trees and bugs in alarming software were ultimately responsible for the power surge that took 100 power plants offline. A previously unknown software bug in a power plant alarm system made itself known, taking the power grids offline, forcing countless businesses to close and dramatically impacting the productivity of a large area of the United States and Canada.
To the information security industry, the most notable result of this accident had nothing to do with the 50 million people directly affected by the outage or the wide swath of the country immobilized by this event, but rather with what the rest of the nation did as they watched. Commerce in California and Colorado continued to function while people in Boston worked and shopped, one eye on the news, but barely effected. The rest of the country's power supply grids held and remained completely unaffected by the massive blackout.
A Dramatic Epiphany for Change:
An epiphany of profound import resulted as the rest of the country went about its business, an epiphany that dramatically changed how corporations and the nation secure their computing infrastructures. The ability of the rest of the country to carry on despite the loss of several key hubs caused some in the security industry to take notice and action.
What happened that day, laid the foundation for what is the perfect security solution: one that ensures that the compromise of a single system will not take down the entire computing network of which it is a part. A robust approach that eliminates the spread of any viral intrusion between systems and preemptively defends against both known and as of yet unknown forms of intrusion in the presence of escalating attacks.
The Tipping Point:
For computer users, 2003 would turn out to be a very bad year and the precursor to an even more ominous 2004. In 2003 the Blaster and SoBig viruses hit the Internet causing millions of systems to become infected only to be followed by the introduction of the Sasser virus in the spring of 2004. Clearly the war on computer viruses was being lost. The capabilities and abilities of hackers' intrusion efforts were outpacing existing security technology and businesses were the sacrificial lambs.
Since the dramatic increase in malicious attacks begun in 2003, the security industry has fought to redefine itself and regain an edge. Every day corporations live with the fact that the scales are "severely tipped" in favor of an information security event that could significantly impede day-to-day operations. Such an event could negatively impact corporate revenues, generate customer-eroding press coverage, contaminate precious compliance standing, and eat into profits at record rates. Security personnel live with the knowledge that they will never work in an environment where software is free of flaws, employees will comply with their security training and mandates, and where hackers can't buy the same software their businesses rely on.
Technology has created this environment of insecurity through the very benefits it sought to provide. The resulting chaos of this viral epidemic has forced corporations and government agencies to demand new solutions to combat an invisible enemy with very good technology skills, excellent intelligence, and far too much time on their hands. These attackers, hackers and "script kiddies" attack a corporations' perimeters, infrastructures and employees with nothing more than "paparazzi and profit" on their minds. The trick is how to break them of this "habit" and effectively take away their edge. The solution, much like the power outage of 2003, lays in examining the whole not the parts.
Much has been written about the motivation behind hackers but to be honest does it really matter? Universally they are persona non grata no matter what intent they have or attack vector they use. What all companies want is for the problem to go away.
The Elephant and the Tiger: The New Security Stance
On extremely rare occasions, there have been documented cases where a starving tiger will attack an elephant. If desperate enough, the tiger will leap on the back of the elephant only to be shaken off time after time with little or no effect on the elephant. After a few attempts the tiger, now exhausted and sensing futility, will leave the elephant alone and seek easier prey. It is this same sense of absolute futility that must be created in order to deter electronic attackers.
Like the elephant, our corporations typically take a defensive posture to protect their infrastructures. This stance gives the more agile, technically savvy and offensively minded attackers (the tigers) an upper hand but only if allowed. In order to break the nefarious habits of cyber attackers and reverse the escalating tide of viral threats, new approaches must be put into place that do not rely on prior knowledge (rules or heuristics) or sacrificial reactions (inoculations and patches) to prevent these attacks. Solutions are needed that are designed to preemptively undermine and directly inhibit the attacker's techniques.
If attackers, regardless of their methods, see little or no effect resulting from their best efforts, "the tiger" will gradually grow tired of attacking "the elephant" and move onto other prey. Over time, the great effort and expense associated with achieving such minimal results will leave the attackers unmotivated and ultimately broken of their habit while corporations continue to deliver the goods and services that fuel their success. It is this basic premise that sets the foundation for the future of information security, a future based upon the principles of continuity and survivability.
Effective security solutions must move away from attempting to stop intrusion by guessing what the next attack vector will be and focus on creating environments (elephants) that will show no visible manifestations of intrusion regardless of some unforeseen or exposed weakness. If the tiger (hacker), with all of its stealth, cunning and speed cannot bring down its prey, the prey has won before the battle has even begun.
From Analogy to Reality:
Only recently are information assurance professionals starting to heed the lessons of 2003 and accept the reality of what the Internet has brought to our doorsteps. Armed with the knowledge that code will always be flawed, people will always be "socially engineered", and that hackers are consumers, computer scientists are starting to look at solutions that provide viral containment, delivering systemic continuity and control. Forward-thinking corporations are beginning to realize and accept that there are no 100% security solutions but that 95% can be nirvana if their computing infrastructures continue to perform through any kind of cyber-weather.
Both private corporations and public organizations are moving toward preemptive command and control solutions and away from reactionary approaches. These solutions not only reduce the threat of enterprise-wide disruption but support compliance efforts, licensing, and the governance of corporate resources. Armed with flexible technologies that concentrate on system cleanliness and data marshalling, companies are reclaiming their resources and becoming the elephants that tigers fear so much.
s
Ken Steinberg is the founder and CEO of Savant Protection. He brings a track record of over two decades in computing and high technology. As founder of the company in 2004, Steinberg has responsibility for its day-to-day operations, overall direction, as well as its technological and business strategies. Prior to Savant, he held senior positions with DEC, Hughes, Hitachi, Softbank and at the John Von Neumann Super Computing Center for the National Science Foundation.
A thought leader in the security/encryption field, Steinberg has addressed national tradeshows including Networld + Interop and HDI. He has also been a radio personality, columnist and contributing author to several regional newspapers and technology publications.

How Familiar Are You With the Information Security Requirements of HIPAA, EPHI and the HITECH Act?

Virtually everyone has heard of HIPAA (the Health Insurance Portability and Accountability Act of 1996). The original act required that organizations use information security mechanisms to protect healthcare information that is processed and stored. HIPAA has had a pervasive impact on health-care organizations as well as insurers, universities and self-insured employee health care programs. Failure to comply with HIPAA could result in a fine of up to $250,000.00 or 10 years in prison for misusing client information.
Fewer people, however, are aware of the implications of the Security Rule for Electronic Protected Healthcare Information that is associated with HIPAA and what is known as the HITECH Act.
All components of the Security Rule for Electronic Protected Healthcare Information, (EPHI), became effective for all covered entities or CE'son April 20, 2006. The security rule for Electronic Protected Healthcare Information was deliberately designed to reflect the requirements of the original HIPAA Privacy Rule. Entities covered by the Electronic Protected Healthcare Information Security Rule must be able to document that the required organizational processes and procedures in place are reasonably implemented for appropriate administrative, physical, and technical safeguards ("HIPAA Security Rules", 2004).
The implications of the EPHI Security Rule are staggering for those who are responsible for providing information assurance. The EPHI rule applies to all covered entities who conduct business with CE's regardless of the industry. The EPHI rule also adds to the expanding list of information assurance laws and regulations (e.g. Sarbanes-Oxley, Graham Leach Bliely and FERPA) with which affected organizations must comply.
The original portion of the security rule for HIPAA was to address a full scope of security standards for the administrative, physical and technical safeguards to shield Protected Healthcare Information (PHI) from disclosure. The adoption of the new EPHI Security Rule now requires the covered entity to:
1. Ensure the confidentiality, integrity and availability of all electronically protected health information that the covered entity creates, receives, maintains or transmits
2. Protect against any reasonably anticipated threats or hazards to the security or integrity of such information
3. Protect against any reasonably anticipated uses or disclosures of such information that are not permitted or required by law
4. Ensure workforce compliance
The follow-on to the security rule of HIPAA is the HITECH (Health Information Technology for Economic and Clinical Health) Act. It was created as part of the American Recovery and Reinvestment Act of 2009. The Act encourages providers to expand the use of EMR or Electronic Medical Records. A variety of financial incentives was included to encourage covered entities to move toward adopting electronic medical records. The assumption was that cost savings would be realized. The HITECH Act set to take effect in 2011 also provides for stricter enforcement and more severe penalties for failure to comply with PHI security rules. In addition to being responsible for the storage and transmission of PHI, covered entities would be required to report data breaches under the HITECH Act.
The information assurance challenges included in HIPAA, EPHI and the HITECH Act are extensive. You need to be technically "on-the-ball" with information security as it relates to the healthcare industry. You now stand to lose a substantial amount of money for being out of compliance, for failing to qualify for incentives and/or damages awarded by juries for loss of confidential patient information.
Learn more about computer security by downloading Dr. William Perry's FREE ebook, "How to Secure Your Computer".
Dr. Perry is the owner of Alliant Digital Services which publishes the Computer Security Glossary. Alliant Digital Services provide high quality information security guidance to individuals and organizations that must plan for the protection of mission critical information in an asymmetric threat environment while complying with industrial- strength information security standards (i.e. COBIT, ISO 27000, FISMA, HIPAA, EPHI and the new HITECH Act).
Dr. Perry is an information security specialist with significant experience as a university professor, author and service provider to various federal agencies including the Office of the Director of National Intelligence, the Department of Defense and the Federal Bureau of Investigation.

What Is an EMP and How Does It Affect Information Assurance?

A vast majority of the nation's critical infrastructure (more than 80%) is privately owned and depends upon a maze of interconnected digital processing technology. We can't afford to lose the integrity of our country's information infrastructure because our way of life would grind to a halt. Providing for the assurance of our modern digital processing infrastructure is, therefore, crucial.
A variety of threats routinely arise against computer systems, including cybercriminals, cyberterrorists and state sponsored cyberwarfare as well as crackers and hackers. Each damaging threat vector places the security of your business and ultimately our country at risk. The federal government now acknowledges the challenge but you must also do so at an individual level.
What is the worse case scenario that threatens our vast digital processing infrastructure?
One overarching threat to our information infrastructure would be the detonation of a nuclear weapon above the earth's atmosphere which would result in an electromagnetic pulse (EMP) wave that would cascade over the surface of the earth below. The resulting high-voltage surge would do damage on a continental scale.
Gamma rays and X-rays generated by the detonation would interact with the exo-atmosphere and strip-off electrons from atoms in the atmosphere. The electrons that are generated from the collisions would propagate throughout the upper atmosphere and downward, spreading out until they impact with the surface.
The pulse wave that strikes the ground would travel a conductive path of least resistance. Delicate in-line or "connected" equipment that contains sensitive electronic computer circuits (central processing units of computers, digital signal processors and programmable logic units) would be significantly damaged or destroyed. Any dependent infrastructure would cease to function.
The likelihood that most of the unprotected digital processing devices would be destroyed in a successful EMP attack is very high. The integrity and availability of any unprotected and vital information infrastructure would be instantly lost.
Telecommunications (land lines, cell phones, etc.), emergency services, radio, television, transportation and distribution would come to a grinding halt. The critical national infrastructure would be thrust back into the 18th century. Modern businesses would lose their continuity and cease to function. Day-to-day life as we know it in America would cease to function. We would have failed to provide for information assurance.
The time it would take to recover from a successful EMP attack, if ever, is unknown. Key equipment that is needed to generate electricity would need to be replaced but is, reportedly, only manufactured overseas.
An EMP attack can also be scaled down. That is, electromagnetic pulse weapons of varying sizes can be built. Any college senior majoring in electronics has the knowledge to build a soda-can-sized electromagnetic weapon that could be directed against smaller targets of opportunity and discharged without a sound.