Author: clarkoperations

  • Opinion: Turing Red Flag Law

    Opinion: Turing Red Flag Law

    Bryne (2016) introduces the concept and history of the Locomotive Act of 1865, also known as the Red Flag Act, that was passed by the U.K. parliament to increase safety and awareness surrounding self-propelled vehicles. The Red Flag Act states that when a vehicle has several carriages attached, a pedestrian with a red flag must lead the vehicle from at least 60 in front of the train. The author explains that the Red Flag Act illustrates the idea that there should be a warning when a large, dangerous machine is incoming. The same concept is applied to artificial intelligence and computer interactions as opposed to human-to-human interactions, where a machine would thereby be clearly labeled a machine so as not to mislead the human user. This concept has been called the Turning Red Flag Law by Toby Walsh, an Australian artificial intelligence professor.

    Potential Benefits for Society

    Artificial intelligence is an increasingly powerful tool that continues to benefit society in new ways. As it increases in complexity, artificial intelligence becomes more difficult to distinguish from human computer users. A Red Flag Turning Law would create a responsibility of maintaining accountability and transparency for all artificial intelligence which would reduce the amount of uncertainty in computer users and might even be a positive influence on the evolution of artificial intelligence itself (which further benefits society as a whole).

    Enforcing transparency through the computer architecture itself mitigates the harmful potential consequences and risks of the indistinguishability between human and artificial intelligence users. If artificial intelligence continues to be utilized in an increasing number of applications, its recommendations will likely be trusted by users more than an anonymous human user’s recommendations due to the enforced regulation within its architecture. The flagging of artificial intelligence could benefit the user’s security and level of transparency by creating a more difficult environment for a human threat actor to intercept the user’s interactions. The human-to-AI authentication methods available to an artificial intelligence model could easily surpass those available to most human users with additional development.

    Threat actors will inevitably continue to utilize artificial intelligence as a tool for malice, and a Turing Red Flag Law would bring additional transparency to the harmful actions of an artificial intelligence so that it could be more easily detected and stopped. Artificial intelligence systems have a history of exhibiting bias, and this behavior can be more easily identified as bias by a human user with a Red Flag Turing Law in effect.

    Potential Consequences for Society

    One of the primary concerns of the technology industry, if a Red Flag Turning Law is put into effect, is that the continued development of artificial intelligence will be stifled or stunted due to creating additional limitations on the software. This limitation would likely not be adopted by a global community which could lead to the potential of advanced rogue artificial intelligence use in non-agreeing organizations. Technology creators might fear legal repercussions in developing their artificial intelligence systems to their full potential. It is vital that a Red Flag Turing Law is not in opposition to the creativity and freedom of experimentation that is necessary for the continuous development of these important technologies.

    Bryne quotes Toby Walsh in his discussion about the use of artificial intelligence in self-driving cars and how the Red Flag Turing Law would be applied within that specific example. He states that human drivers often make far more mistakes on the road than artificial intelligence and are a more dangerous threat on the road than a self-driving system. Therefore, there would be a potential benefit of the ability to distinguish between human drivers and artificial intelligence systems on the road because the human driver could be recognized as less predictable, more dangerous, and requiring of more attention. Simultaneously, the artificial intelligence drivers could be expected to drive predictably, follow traffic rules appropriately, and fair better in low visibility conditions. This entire concept adds to the discussion about the value inherent in knowing whether a user is human or computer.

    Reflecting on the Author’s Proposal

    The development of artificial intelligence systems requires balancing the forces of regulation and rapid development so that the technology continues to progress appropriately. The added transparency and accountability from a Red Flag Turing Law could serve as powerful benefits to adoption, while the slowing of development and attention to regulation present considerable challenges to implementation and development. Regardless of whether a Red Flag Turing Law is adopted in its current conceptualization, society must develop a way for artificial intelligence algorithms to provide accountability and transparency, as well as detection and intervention of artificial intelligence’s potentially harmful behavior.

    Armed with artificial intelligence and machine learning tools, threat actors will make many attempts to disguise their artificial intelligence systems with hopes of masquerading as human users; I think it is extremely likely that tools to detect artificial intelligence algorithms for authentication will be brought to use. I think that defensive artificial intelligence models will quickly become more adapted at detecting other artificial intelligence algorithms and labeling them as artificial intelligence with more proficiency than is possible by humans. Due to the evolutionary nature of cyber security and artificial intelligence tools, the tools used to detect artificial intelligence will likely be an AI trained on data models of all known Ais. This technology would function similarly to anti-virus in that it uses signatures of the algorithm and matches them against a collection of signatures in a database of known AI algorithms.

    Over enforcement of a law like a Red Flag Turing Law would likely disadvantage small businesses and individuals from developing artificial intelligence systems as rapidly as large corporations because of the regulatory attention that must be paid and the severe penalties of potential artificial intelligence mistakes. These regulations would lead to longer testing cycles and potentially higher ethical concern when working with artificial intelligence, which I think is a positive and necessary change.

    AI models are trained on data that is created by humans and the system inherits all the bias, prejudice, and hypocrisy portrayed in the training data. Attention to the development of artificial intelligence regulation to correct the inherit problems from the training data will hopefully cause society to address those same issues as they exist in people, as a society. I hope that, as we make societal decisions surrounding these issues, we are brought into a global conversation to discuss all aspects of these issues so that we can begin to shape the architecture of the next generation of artificial intelligence tools. Without transparency, accountability, and due diligence given to ethics the benefits of artificial intelligence tools will not optimally serve the common goals of humanity. I do not look forward to a future with many different personalities of artificial intelligence that have been developed with various intent. The potential of artificial intelligence as a unifying element and technology for global communication and understanding is unprecedented, its significance exponential and similar in effect to the internet and telephone.

    References

    Bryne, M. (2016). AI Professor Proposes ‘Turing Red Flag Law’. Vice Mediahttp://motherboard.vice.com/read/ai-professor-proposes-turing-red-flag-law

  • Anonymity in Cyberspace

    In this information age, large technology corporations harvest the personal data of millions of individuals to collect demographic information that they can apply to their products and advertising endeavors.  Private citizens desire situations in which they can protect their personal data through anonymous action; and inversely, users want proper authentication credentials and authorization systems to protect access to their electronic business arrangements.

    I don’t believe that the conversational debate on this topic should resolve in a binary answer of whether anonymity should be preserved in cyberspace because there are differing types of practical applications which benefit from either anonymity or authentication. If the world wide web is continually used for both casual recreation and serious business applications, there will be a need for both types of functionalities to be utilized to create satisfied users. Ideally, our business communications and transactions should be secured, encrypted, and only available to properly authorized and fully authenticated users. However, it is helpful and comfortable to be able to maintain anonymity as a casual user and utilize the protection of anonymity to protect freedom of speech and the identities of vulnerable users from possible threat actors.

    The Usefulness of Anonymity

    Throughout history, anonymity has proven to be useful in protecting vulnerable people for many legitimate reasons. Journalists often rely on hiding their personal information to protect themselves from threats to their person when publishing controversial ideas or when writing with criticism toward authority figures. Anonymity also allows writers to disconnect from their subject matter in a way that they might hope allows people to withhold the prejudice that comes with knowing who the author of a work is. According to Hruska (2011), the founder of Facebook has stated that all anonymity should be abolished from the internet, elaborating that he believes personal anonymity leads to a higher chance of negative or anti-social behavior. I don’t believe that his statements reflect the implications of all anonymity online, but instead pertain particularly to the Facebook service which also profits less from anonymity and profits more from a strategy of personal data collection and user verification. In opposition to Mark Zuckerberg’s opinion on digital anonymity, I believe that there are very useful applications for anonymity and that the determination of whether personal verification should be obtained is situational. I think that it is time for the governing bodies to accept that the many applications of today’s internet have outgrown the regulations that govern the physical hardware systems that powers them, and new legislation should be considered that promotes informed consent on behalf of private citizens and their data privacy.

    The Necessity of Personal Authorization

    There are so many business transactions and accounts that exist on the world wide web and individuals all desire proper authentication systems in place so that they are the only verified user of their accounts and sole signer of their transactions. A verification process does submit personal information to a 3rd party, but that does not mean that the 3rd party must engage in mass data collection, trading, and sales. The organization’s collection of qualifying personal information helps protect a user’s account from people that do not possess that information which contributes to authentication and helps to maintain the economic integrity of the relationship. However, there are plenty of types of interactions on the internet that do not require verification and can be used more comfortably in complete anonymity. Just like in our non-digital interactions with people in society, information is naturally disclosed on a need-to-know basis. People don’t feel comfortable sharing all their personal details in the first few conversations or with someone they don’t know well because of possible security risks. This is an example of how we use anonymity in everyday life to assert authorization when providing our personal information to others. The world wide web has similar situations and interactions in which it is beneficial to preserve personal anonymity to protect personal data and exercise free speech. Hruska (2011) points out that anonymity has been described by the United States Supreme Court as vital to the freedom of speech, which I think should also be respected in the internet platforms and the systems’ informational design.

    Is Anonymity in Cyberspace an Illusion?

    In today’s internet, when a user makes a connection to a website, their computer’s details are sent through a vast network of networks before it reaches the intended destination leaving behind a trail that is easily tracked. Because of this physical limitation on the potential anonymity of the medium, I believe that digital anonymity is somewhat of an illusion. Digital anonymity can be created when an organization’s operations are designed to collect the minimal amount of user data required to achieve the necessary functions of the product or service. It is in the hands of the organization and user who must take responsibility for possible security risks and foster their relationship’s trust to maintain a comfortable sense of digital anonymity. Lufkin (2017) from BBC, states that he believes digital anonymity allows people to have exciting experiences without fearing the consequences of recognition or retaliation to themselves. Relating to psychology, he believes that our individual definition of self is made up of both our perception of ourselves and a culmination of how other people view us. Although that any interaction on the internet can be traced with enough time, it is equally important for web developers to create spaces that provide users with an easing sense of anonymity and proper user verification as is applicable to the specific type of interaction.

    Part of the illusion of anonymity that initially surprised me was, as Lufkin (2017) states, that personal demographic data is still bought and sold through large technology companies even if the subject individual is not a user of that service or does not possess an account with that company. Corporations such as Facebook are still able to collect data about individuals through other methods such as their Facebook Pixel which tracks users on many different websites outside of Facebook. Inherently, there is no anonymity on the internet that is legally protected out of the scope of the freedom of speech.

    Is Secure Authorization in Cyberspace an Illusion?

    Secure authorization is generally provided through the roles assigned by the server administration after authentication. Authentication systems are constantly challenged in new ways as hackers and cyber security professionals battle it out in endless advancement of their offensive and defensive tools and systems. Huge collections of personal data that exist within these large companies’ user accounts are popular targets for criminals because this personal information usually leads to qualifying information that allows them to access business and financial accounts. Secure systems sacrifice convenience for more security; so, if we want to enjoy the benefits of conducting our business on the internet, we should recognize the value of authentication and encryption systems like biometrics and passkeys. The government has a direct interest in reducing the level of possible anonymity on the internet toward more transparency so that it becomes easier to identify and solve domestic threats of terror and other forms of crime that can be traced through our national networks.

    Anonymity for Human Rights Protection

    The United Nations Human Rights Office (2015) writes that the improvement of digital security is imperative to the success of all interactions with the United Nations to work toward their goal of creating a connected, protected, and stable world environment. Within their concerns lie the digital security of countless people who rely on the protection of freedom of speech and some form of digital anonymity to perform their job tasks without adding to the risk of personal endangerment. Moyakine (2016) writes that anonymity on the internet is critical to the maintenance of our human rights and fundamental freedoms, and our personal data and free expression should be protected. Personally, I believe that the disclosure of personal data to corporations allows threat actors to directly target individuals and is an obvious personal security risk. The internet has the potential to facilitate the greatest conversational progress that humanity has yet achieved, but if users’ personal data can be targeted and some form of digital anonymity is not in place then people will be discouraged from exercising their freedom of personal expression due to considerable negative consequences.

    Summary

    When discussing the subject of digital anonymity, we must also consider the importance of free speech, privacy of personal information, and the preservation of our human rights. It has become common for large technology companies to develop technologies that appear to challenge our current legislation’s technical knowledge or appear to create a situation that has no prior legislation. I believe that this attempt at overcomplication is more of an attempt to create a monopoly within a trending market, often at the expense of individual data privacy and free speech. Optimistically, I hope that advances in encryption and authentication techniques can create a justifiable sense of security in the world wide web while adopting a need-to-know style strategy toward data privacy to protect users from dangerous personal data exposure.

    References

    Hruska, J. (2011). The need for anonymity in a digital age. ExtremeTech. https://www.extremetech.com/internet/92096-the-need-for-anonymity-in-a-digital-age

    Lufkin, B. (2017). The reasons you can’t be anonymous anymore. BBC. https://www.bbc.com/future/article/20170529-the-reasons-you-can-never-be-anonymous-again

    Moyakine. (2016). Online Anonymity in the Modern Digital Age: Quest for a Legal Right. Journal of Information Rights, Policy and Practice, 1(1). https://doi.org/10.21039/irpandp.v1i1.21

    United Nations Human Rights Office of the High Commissioner. (2015). Human rights, encryption and anonymity in a digital age. United Nations. https://www.ohchr.org/en/stories/2015/06/human-rights-encryption-and-anonymity-digital-age

  • Why Organizations Use Risk Management Frameworks

    Organizations want to implement a risk management framework for the same reason that they would want to have insurance coverage or a security system. There are many different types of risks for which an organization can be liable, including hazard risk, financial risk, operational risk, and strategic risk. A risk management framework can provide a structured way to assess, organize, prioritize, and control risk, providing structured processes and contextual insight to organizations.

    The benefits of implementing a risk management framework include the ability to make more informed decisions, reduce costs by reducing the likelihood of incidents, and understand the potential threats that can affect the organization. A risk management framework can give an organization an advantage due to being designed to address regulatory compliance within the specific industry, as well as provide stakeholders with additional confidence and understanding of risk tolerance.

    The downsides of implementing a risk management framework include the need for an organization to interact with a high level of complexity, which also require large amounts of resources to be properly managed. Convincing an organization to adopt a risk management framework can be difficult to provide an accurate figure of return on investment that would clearly outweigh the difficulty and resource cost of adopting the framework.

    References

    Marker, Andy. (2021). Enterprise Risk Management Frameworks and Models. Smartsheet.https://www.smartsheet.com/content/enterprise-risk-management-framework-model

  • Which Technology Poses the Greatest Cybersecurity Risk?

    The internet of things (IoT), blockchain technology, artificial intelligence, and quantum computing all present risks to the future of internet security; however, I believe that the internet of things poses the largest security risk by unnecessarily connecting countless additional devices to a global network.

    The potential convenience of knowing how much coffee is left in the coffeepot inspired computer technologists at the University of Cambridge to develop the first web cam application which monitored the coffee levels in the breakroom with low-framerate, grayscale video (Kesby, 2012). Thirty years after this first coffee pot monitoring system went online in 1993, we now have a wide variety of internet-enabled devices that serve countless purposes, but which collectively grow the attack surface of its parent networks.

    Not only does each different model of IoT device have its own set of vulnerabilities that attackers could exploit, but compromised IoT devices could also be used in a botnet to perform distributed denial of service (DDoS) attacks (Abbass et al., 2019).

    Security for internet of things devices is still in its infancy, and standards will likely be developed soon which will lower the overall security risk of integrating IoT devices within a network. However, for the present, most IoT devices do not even allow users to reset the default login credentials of the device which represents a near complete lack of security embedded in an internet-enabled device (Evans, 2019).

    References

    Abbass, W., Bakraouy, Z., Baina, A., Bellafkih, M. (2019).  Assessing the Internet of Things Security Risks.  Journal of Communications Vol. 14, No. 10. http://www.jocm.us/uploadfile/2019/0909/20190909054049213.pdf

    Evans, A. (2019). Managing Cyber Risk. Taylor & Francis. https://online.vitalsource.com/books/9780429614262

    Kesby, R. (2012). How the world’s first webcam made a coffee pot famous.  BBC World Service.https://www.bbc.com/news/technology-20439301

  • Quantum Computing & Cybersecurity

    What is quantum computing?

    Quantum computing represents the third era of computing hardware which emerged after analog and digital computers, and which applies the laws of quantum mechanics to the world of computer science. Instead of using a digital bit to store a binary state, a quantum computer uses a quantum bit (qubit) to store binary and indefinite states within the subatomic particle of the qubit. Quantum computers utilize laws of quantum mechanics such as quantum entanglement, using the probability of entangled particles being in a certain state at a specific moment in time to quickly solve complex problems that contain many possible solutions (Smith, 2021).

    Does quantum computing present a cybersecurity threat? If yes, why? If no, why not?

    The capabilities of a fully developed quantum computer would theoretically pose a massive cybersecurity threat to our current infrastructure. The quantum mechanical properties of the sub-atomic particles within a quantum computer allow for many possible solutions to a problem to be considered simultaneously, which leads to solving some types of complex problems much faster than is possible with classical computers. One of the most discussed ramifications of a fully functional quantum computer is the ability to quickly determine the two prime factors of large numbers because determining those key pairs would crack the types of public key encryption systems currently utilized by the world wide web (Denning, 2019). Once a quantum computer can reliably surpass the performance of classical supercomputers, the current methods of encryption will essentially begin to prove obsolete against an advanced quantum computer. Essentially, all current encryption algorithms can be solved by a computer given a long enough period but the keys that take classical computers years to crack can potentially be solved by quantum computers in a fraction of the time. Researchers are currently working to create new algorithms and forms of cryptography that can resist the potential attacks of quantum computers; as well as new forms of key exchange based on quantum hardware.

    What role would quantum computing have on cryptography?

    The role that quantum computing takes in cryptography involves its ability to consider the many possible solutions to a problem in parallel instead of one at a time (Evans, 2019). In a brute force attack, considering all possible solutions simultaneously would theoretically provide a solution exponentially faster. These game changing effects of quantum computers on offensive cyber security presently creates a pre-emptive need for quantum resistant encryption algorithms to combat the inevitable emergence of quantum powered brute force attacks in the coming quantum era of computing.

    One defensive solution that provides some peace of mind against quantum attacks is to simply use longer keys (Denning, 2019). Denning writes in American Scientist that a 128-bit key has the same protection against a classical computing attack as a 256-bit key has against a quantum computing attack utilizing Grover’s algorithm.

    What country is winning the quantum computing arms race?

    According to Smith (2021), the United States and China are headlining a race to fully develop the capability of quantum computing and be the first nation with the ability to bypass information security as we know it. Each of these world superpowers is supported by several companies that are pushing the leading edge of quantum computing technology by developing a variety of quantum computing solutions and hardware. China has already achieved some major milestones in quantum computing such as the first cloud-native quantum computing platform, obtaining a solution in a fraction of a single percent of the time that it would take the fastest supercomputer in the world to obtain, and combining quantum computing with artificial intelligence. The key to winning the quantum computing arms race is likely to reside in the amount of collaboration and funding between government organizations and private companies. Regardless of what nation wins the quantum computing arms race, there is an expectation to allow developing nations to access the power of quantum computing through a cloud service, thus providing a global benefit.

    What national security implications would quantum computing present to the US if China beats them?

    If China can beat the United States in the race to quantum supremacy, all US intellectual property as well as possibly some classified government level data could potentially be quickly compromised and leveraged toward the disadvantage of the United States’ government, businesses, and citizens (Schappert, 2023). The winner of the quantum computer race would also have the earliest access to further applications of quantum computing such as developments in medicine, physics, artificial intelligence, and machine learning.

    References

    Denning, D. (2019). Is Quantum Computing a Cybersecurity Threat? American Scientist.https://www.americanscientist.org/article/is-quantum-computing-a-cybersecurity-threat

    Evans, A. (2019). Managing Cyber Risk. Taylor & Francis. https://online.vitalsource.com/books/9780429614262

    Schappert, S. (2023). Quantum computing race explained: fast and furious. Cybernews.https://cybernews.com/editorial/quantum-computing-race-explained/

    Smith, C. (2021). Competing Visions Underpin China’s Quantum Computer Race Alibaba builds their own qubits, Baidu remains quantum hardware-agnostic. IEEE Spectrum.  https://spectrum.ieee.org/alibaba-baidu-quantum-computer-race

  • What is Vendor Risk Management?

    Vendor risk management describes the combined processes of third-party vendor management and cybersecurity risk monitoring (Tunggal, 2023). Third-party vendors include cloud solution providers, information technology companies, or other vendors of other outsourced services. Healthy connections between a company and a vendor require the utilization of high-level assessments for security controls in relationship management. A vendor risk management planis a service level agreement that details the arrangement between the company and the vendor and details how they plan to maintain compliance and ensure vendor performance overtime. Risk scoring methods and algorithms are used to generate quantifiable data that can help organizations conduct better risk management practices with the many third-party vendors also in consideration.

    A company that uses any sort of outsourcing or otherwise obtains a product or service should understand and document the risks involved with third-party vendors and have an organization-wide plan to minimize the specific risks associated with each third-party vendor that the company is involved with. Currently, it is not uncommon for the operations of organizations to utilize the products and services of over 1000 third-party vendors. It is imperative that the security risks involved with third-party relationships are managed throughout the entirety of their lifecycle so that the attack surface and risk to the organization can be minimized.

    Third-party and Fourth-party Vendors

    While a third-party vendor includes any outside provider of a product or service to the organization, a fourth-party vendor describes a supplier of a third-party vendor which can indirectly influence the organization as a supplier to the third-party vendor (Chipeta, 2023). Fourth-party risk basically aims to measure the risk that is inherited through the supply chain. To an information security team, the risks associated with third-party vendors and fourth-party vendors pose equal levels of threat and both contribute to the same overall attack surface which must be integrated into the vendor risk management plan. The existence of fourth-party vendors creates an environment that makes it important for each organization to have their own individual vendor risk management programs. It is also important for organizations to try to gain as much information about their vendors and supply chain as possible so that they can receive relevant information in a timely fashion which might warrant a response or change within the organization in the case of a security incident. If a fourth-party vendor is the victim of a data breach, the security of the third-party vendor cannot be assumed to protect the organization from harm. Regardless of where the breach occurred, the organization is responsible for its complete attack surface which includes all third-party and fourth-party vendors. Fourth-party vendors can be challenging to obtain information about or their presence might even be unknown to the organization.

    Vendor Security-focused Assessments

    Most of the cybersecurity breaches that are reported are caused through one of many third-party vendors which provide products or services to the organization (Evans, 2019). Because only 40% of current applications are stored on-site, most involve a third-party service vendor such as a cloud service provider. It is important that an organization’s data is accessible only to approved vendors and only while they require access to complete their tasks. Communication and transparency should be exercised and maintained between an organization and their third-party vendors throughout the life of their agreements; the documentation and information surrounding these relationships and agreements are part of the focus of vendor security-focused assessments. Other common areas of focus that are included in the vendor security-focused assessments are applicable governmental regulations, geographical data restrictions, privacy policies, encryption, offboarding security procedures, and disaster recovery planning.

    Industry Standard Questionnaires

    There are several industry standard questionnaires that companies can utilize in tandem with a vendor risk program to benefit the security posture of their organization such as Panorays (Goldman, 2023). Along with vendor attack surface assessment, vendor risk assessments, and continuous monitoring, industry standard questionnaires compose the four key steps that Panorays recommends for a comprehensive third-party risk management process.

    Another example of an industry standard questionnaire service is UpGuard; their software service offerings include continuous attack surface monitoring and protection from third-party data leaks in addition to their questionnaires (Tunggal, 2023).

    Opinion: How to Ensure Vendors Meet Security Requirements

    In my opinion, the best way to ensure that vendors meet an organization’s security requirements is to adhere to an industry-standard framework and set of standards as an organization and work with third-party vendors that also use standard frameworks and standards. Companies do not have to make scrambling attempts at meeting security requirements because frameworks created by the hard work of standards organizations will provide organizational structure and a set of procedures that can ensure compliance when completed properly. Secondly, I think that to a lesser extent accountability through transparent and logged communication including industry standard questionnaires can help quantify the levels of risk involved with third-party vendors. Certifications can attest to security compatibility in organization-vendor relationships.

    References

    Chipeta, C. (2023).  What is Fourth-Party Risk? UpGuard. https://www.upguard.com/blog/what-is-fourth-party-risk

    Evans, A. (2019). Managing Cyber Risk. Taylor & Francis. https://online.vitalsource.com/books/9780429614262

    Goldman, Dov. (2023). How Vendor Risk Management Reduces Third-Party Risk. Panorays.https://panorays.com/blog/what-is-vendor-risk-management/

    Tunggal, Abi T. (2023). What is Vendor Risk Management (VRM)? 2023 Edition. UpGuard.https://www.upguard.com/blog/vendor-risk-management

  • The Trojan Horse Virus Type in 5 Examples

    The Trojan Horse Virus in computing is named after the story of the Trojan horse in the works of Virgil and Homer in which soldiers hid themselves inside the body of a large wooden horse to stealthily ambush the city of Troy (Fortinet, 2023). Similarly, a Trojan horse virus is composed of malware that is disguised as a genuine software application or file. Once the Trojan horse virus as successfully breached a system’s defenses by being accepted by a user, the malware is free to run its course within the host network.

    The Inosoft VisiWin 7 2022-2.1 Trojan exploit that was documented in August of 2023 allows the creation of an insecure folder which enables the manipulation of files and can result in escalation of user privileges (Shinnai, 2023). This exploit is capable of compromising the entire system and has a CVSS severity rating of 7.8 which is high. The Inosoft VisiWin 7 2022-2.1 Trojan exploit was reported by Carlo Di Dato for Deloitte Risk Advisory Italia.

    In April of 2023 a Trojan horse-powered attack in Diasoft File Replication Pro 7.5.0 was published that replaces an executable file that already has “LocalSystem” rights with a Trojan executable that is then executed allowing escalated privileges. This vulnerability has critically high severity at a 9.8/10. The exploit was documented by Andrea Intilangelo.

    There is a vulnerability that is exploitable by a trojan horse virus, documented in February of 2023, which involves the installer applications of ELECOM Camera Assistant and QuickFileDealer (JVN, 2023). Similar to some other recent Trojan horse attacks, this attack includes an issue that can insecurely load Dynamic Link Libraries (DDL). The running application provides privileges to which arbitrary code may be executed. There is a solution available from the developer in the form of an updated installer application.

    Yet another example of a trojan horse attack that utilizes insecurely loaded Dynamic Link Libraries involves Sony Content Transfer for Windows from the Sony Corporation (JVN, 2023). Privileges needed for arbitrary code executed are provided through the installer’s privileges. The effect and solution of this vulnerability are some what limited because the software is no longer in distribution, however potential for malicious distribution is possible.

    A fifth example of a trojan horse attack that was recently documented uses a similar privilege escalation strategy with the trojan horse executable of Panini Everest Engine 2.0.4 (NIST, 2023). This vulnerability comes from the use of an unquoted path that runs the service as “SYSTEM”. The impact of this vulnerability is escalation to system privileges and is scored at 7.8/10 in severity.

    References

    (2023). CVE-2022-39959 Detail. National Vulnerability Database. https://nvd.nist.gov/vuln/detail/CVE-2022-39959

    (2023). JVN#60263237 The installers of ELECOM Camera Assistant and QuickFileDealer may insecurely load Dynamic Link Libraries. JVN. https://jvn.jp/en/jp/JVN60263237/

    (2023). JVN#40620121 The installer of Sony Content Transfer may insecurely load Dynamic Link Libraries. JVN.https://jvn.jp/en/jp/JVN40620121/

    (2023). Trojan Horse Virus. Fortinet.

  • The Importance of Ethics in Penetration Testing

    Ethics are paramount to conducting penetration tests. Technologists conducting penetration tests must always closely obey laws and behave in a strictly ethical fashion to maintain a high level of trust because penetration tests aim to determine the exploitability of a system’s weaknesses without damaging or negatively affecting any systems in the process (Faily et al., 2016). Penetration testers are consistently faced with situations that can increase the chance for unethical behavior or implicit bias to take place, which Faily et al. refers to as “ethical hazards.” These ethical hazards include situations with legal ambiguity, tests that involve a human target, tensions between offensive security team and defensive security team activities, and a client’s possible indifference to security recommendations. Each situation that purposes an ethical hazard requires a high ethical standard and attention to ethical responsibility in the performant so that the integrity, confidentiality, and availability of the systems can be secure.

    In the world of penetration testing, legal written authorization is what is referred to as a “get out of jail free card” and obtaining it is a key process to a legal ability to conduct pen testing. Penetration testers should be scrupulous, transparent, and thorough in their documentation because proper documentation is fundamentally the only reason that penetration testing can be performed legally. Documentation also provides clients an understanding of the complete scope of work and builds trust with the penetration testers (Gillam, 2023). Faily et al. (2015) explains that hacking a system requires a set of technical and creative skills to succeed, but penetration testing has an added constraint of protecting both the dignity of users affected by the test and protecting the systems involved from danger created by the test. When a penetration tester makes an incorrect choice in an ethical decision, they can easily face criminal charges.

    References

    Faily, Shamal; McAlaney, John; Jacob, Claudia. (2015). Ethical Dilemmas and Dimensions in Penetration Testing. Bournemouth University. https://cybersecurity.bournemouth.ac.uk/wp-content/papercite-data/pdf/fami15.pdf

    Faily, Shamal; Jacob, Claudia; Field, Sarah. (2016). Ethical Hazards and Safeguards in Penetration Testing. https://dl.acm.org/doi/pdf/10.5555/3114770.3114793

    Gillam, Jason. (2023, March 9). SecureIdeashttps://www.secureideas.com/knowledge/what-are-the-ethical-and-legal-considerations-for-penetration-testing

  • What is a SIEM tool?

    A Security Information and Event Management System (SIEM) combines the security management of information and events into dashboard graphical user interfaces which display an aggregation of data, including anomalies and alerts within the system (Gillis & Rosencrance, 2022). Beyond a SIEM tool’s detection capability, it can also take reasonable action based on events or notify other controls to change status after a suspicious event. SIEM tools collect data from logs of many different host systems which can then be viewed in a navigable graphical user interface, processes and events can be correlated with timestamps and alerts, suspicious activity can be quickly detected based on preset parameters. SIEM tools streamline the data analysis process that large companies face by drawing attention to only the most important alerts, events, and problems; and automating some of the resolution processes so that a security solution can be expedited.

    SIEM are helpful tools for organizing security defense and cyber responses for corporations because they provide a centralized perspective that is built by continuously analyzing the data associated with all users, business assets, events, and interactions (“What Is Security Information…,” 2022). Security teams in corporations can have the most relevant and conclusive information about their network operations in a convenient, “single pane of glass” display. SIEM alerts allow corporate management to become aware of time-sensitive anomalies within the network that could be potentially dangerous and costly if not immediately handled appropriately with the aid of an aggregation of relevant information involved in the decision-making processes. SIEM tools’ interfaces allow a flexible range of customization that can suit many purposes of managing assets within a corporation. User behavior patterns can be analyzed in forensic investigations or audits, which is equally useful to corporate management as real-time monitoring and legal or regulatory compliance.

    An example of a SIEM is SolarWinds SIEM made by SolarWinds (“SIEM Tools,” n.d.). The application’s primary purpose is to provide a centralized point of access for logging, threat analysis, response, and reporting. The price of a SolarWinds SIEM subscription starts at $2,877; the company also offers a fully functional 30-day trial of the software. The capabilities of this SIEM software are log collection, the ability to quickly find and focus on relevant information, and to assist in creating an improvement to reaction time to identifying suspicious behavior. SIEM software such as SolarWinds SIEM allows a broad scope of an organization’s security posture to be visualized and studied in a real-time graphical user interface environment so that an organization can mitigate security threats, improve compliance, and optimize their defense strategy. SIEM tools can help distinguish between data and and external threats, make updated decisions based on past data, and automate many processes that save valuable time in each stage of an effective cyber security strategy.

    References

    SIEM Tools. SolarWinds. https://www.solarwinds.com/security-event-manager/siem-tools

    Gillis, Alexander S.; Rosencrance, Linda. (2022, December).  Security Information and Event Management (SIEM). TechTarget. https://www.techtarget.com/searchsecurity/definition/security-information-and-event-management-SIEM

    (2022, August 1). What Is Security Information and Event Management (SIEM)? Splunk.https://www.splunk.com/en_us/data-insider/what-is-siem.html

  • Ethics of Facial Recognition Technology

    Government and Business Applications of Facial Recognition

    The federal government utilizes facial recognition software commonly at federal points of interest such as border crossings and within their own records for FBI investigations. There are policies in place that restrict the ability of the FBI to use photographs as positive identification within a case, however the organization is free to utilize photographs as clues to possible identifying evidence. The FBI uses a large repository of photographic data called the Interstate Photo System (IPS) and acts upon this data with a Next Generation Identification System (NGIS). This data corroborates individuals’ corresponding fingerprint data with face photos and other identifying information for the access of the FBI. According to Brandom (2021), on the state government level, a few states such as Massachusetts and Maine have passed legislature with intent to limit the ability of state governments to use facial recognition software.

    ACLU and Criticism of the Technology

    The American Civil Liberties Union (ACLU) has made criticizing statements regarding the privacy issues surrounding facial recognition software and have stated that they are handling the issue with seriousness and concern. Balli (2021) stated that the creators of Facebook, the Meta company, decided to stop utilizing facial recognition software within their platform in response to the declared privacy concerns of their users and those of government. Brandom (2021) stated concerns about an innate racial bias within facial recognition technology that raises additional significant issues surrounding the topic.

    Facial Recognition and Individual Privacy

    Facial recognition technology becomes in direct opposition to individual privacy when installed in public spaces. The technology could be implemented to use as a biometric authentication method for retail purchases, entrance keys, or even for criminal penalties. According to PrivacyRights.org (2011), prevalent use of facial recognition software in a public space would lead to complete loss of individual anonymity while improving the commercial ability of demographic targeting in marketing and sales. I believe that our individual anonymity is a large part of what makes us feel comfortable and safe in public environments. I think that with broad application of facial recognition software we would lose that sense of comfortable anonymity within society’s public spaces.

    Private Businesses’ Potential Abuse of the Technology

    The capabilities of facial recognition technology are not yet common knowledge, and the ethical considerations of its possible applications are still being considered by the technology community. Facial recognition is often used in military applications for targeting individuals, but the same basic technology is also available for commercial use by private business. The scalability of facial recognition software can easily create an over-arching and controlling architecture that has a high risk of important personal data being leaked in the case of a breach.

    Advocacy for Facial Recognition

    There is a market understanding that many customers will push back at a privacy over-reach if it becomes too concerning. However, the commercial world will utilize any tool at its disposal if it aids in reaching more customers, making more sales, or increasing profit margins. Facial recognition allows businesses to give personalized experiences to customers as they enter a store or could target them with coupons after they were recognized at a corresponding location. The ethical components of facial recognition technology will find polarizing effect upon the minds of technology leaders, some of whom will embrace the technology while others will choose not to use it citing ethical concerns.

    IT Manager’s Perspective

    As an IT manager, I would not encourage the use of facial recognition software in commercial applications. On the government level, I think that facial recognition software has valuable and viable applications in crime prevention and international security. The policies I would support as an IT manager would prioritize the individual privacy rights of my organization’s customers over leveraging technology with possible ethical ramifications. As a business, I would not want the legal responsibility of housing and protecting sensitive personal data from possible data breaches, even with the use of a third-party partner. I stand for proper authentication methods and a minimalist, need-to-know style of personal data sharing.

    References

    Balli, E. (2021). The ethical implications of facial recognition technology. Arizona State University. https://news.asu.edu/20211117-solutions-ethical-implications-facial-recognition-technology

    Brandom, R. (2021). Most US government agencies are using facial recognition. The Verge. https://www.theverge.com/2021/8/25/22641216/facial-recognition-gao-report-agency-dhs-cbp-fbi

    Greco, K. (2019). Facial Recognition Technology: Ensuring Transparency in Government Use. FBI.gov. https://www.fbi.gov/news/testimony/facial-recognition-technology-ensuring-transparency-in-government-use

    (2011). Facial Recognition is a Threat to Your Privacy. PrivacyRights.org. https://privacyrights.org/resources/facial-recognition-threat-your-privacy