Skip to main content

The Network Perimeter: This Time, It’s Personal For All Of Us.

 Botnets and IoT devices create an ideal storm for IT workers fighting for the safety of WFH staff.

900+ Free Network & Internet Vectors - Pixabay

From a historical perspective, the state of cybersecurity will not take the high payoff away from the COVID-19 epidemic. However, one is deeply affected by the other, and only time will tell what the full collapse will be. The first six months of 2020 have seen significant progress in the world of cyber threats, and it is important for future security strategies to look at what has already happened.

Most importantly, the Homework Authority (WFH) has made great strides in corporate networks almost overnight, with cyber rivals starting to exploit them for their own benefit. This has led to an increase in exploitative efforts against routers-grade routers and internet-of-things (IoT). In the first half of this year, exploitative efforts against several consumer-level routers and IoT devices were at the top of the list of acquisition of internal security systems (IPS). And then there were the malware botnet.
Mirai and Gh0st

Mirai has become a very active botnet in early May, which is likely to be driven by the growing interest of attackers in targeting old and new threats to consumer IoT products. This practice is important because it suggests that cybercriminal perpetrators want to establish a beachhead in business networks by exploiting devices that WFH employees may be using to communicate with a business network. Somehow, the perimeter of the company’s network extends beyond the home - and that’s not a good thing.

Attackers have also been using Gh0st, an old family of malware-botnet criminals, in campaigns targeted at WFH users and applications. Gh0st is a remote access botnet that allows the evil character to take full control of the infected system, install access keys, provide live webcams and microphone feeds, download and upload files, and perform other functions.
Redesign

The presence of vulnerable devices on home networks greatly increases the attack area for organizations with a large number of remote workers. Therefore, organizations should consider options for achieving the same level of protection for WFH employees as they had in the office.


With organizations still operating primarily in remote areas, it seems likely that remote work will play a significant role in business by 2020 and beyond. Even if companies are still limited and unable to send people back to office, or develop flexible remotely remote policies to better meet the needs of their employees, these businesses must ensure that their telecommunications strategies can support and protect long-term telecommunications.

As organizations shifted to WFH mandate, many were unaware of just some of the weaknesses and challenges of their infrastructure. Businesses made changes and added to their positions so quickly that it was difficult to understand the results below. Costs are now beginning to emerge with interoperability challenges, data-privacy concerns, operational corruption and increasing complexity. IT workers who were already nervous about managing the status quo now have a lot to deal with in tools and services that are not built with unity and automation in mind.

Some organizations use small firewalls directly in their “large users” homes to create a secure enclave, which protects the organization’s sensitive data from the home network. This use of a firewall directly in the home office can provide users with the same type of wireless and wireless connectivity they would have in the office, with full business firewall protection, all remotely managed so that the IT team can fully see the edges of multiple networks. This enables large users to run a business as usual from their home offices while ensuring high levels of protection, apparently because home networks are a weak foundation for the entire system. If organizations are not protected from that threatening vector, they leave themselves exposed, which is what CISO is learning and that is why they are embracing long-term solutions for remote workers.

In addition, organizations place great emphasis on the concept of access to the zero-trust network. There are two reasons: first, they use multiple VPN channels that need to understand and verify who the users are; and second, they have users on many types of devices who now have access to the company's network.

Finally, there is the recognition of the need for integrated network operations and security, as well as the need to effectively protect dynamic cloud environments. Network infrastructure must allow for radical change and integration of new technologies and must have integrated (and automatic) security functions to maximize efficiency and reduce complexity. This approach needs to extend from branch to edge, and the data center to the cloud, with consistent policy and central visibility across management.
Filling Spaces

The epidemic has changed the way we operate and how we protect our networks - perhaps permanently. Defenders have to deal with not only the vulnerability of their networks, but also the many vulnerabilities exploited in the wild. Organizations need solutions that allow for business continuity, supporting employees as they work from other locations, while ensuring a high level of security. Consider the ramifications and best practices mentioned above, and consider what security measures might be required.

Aamir Lakhani, is a cyber security researcher and works at Fortinet's FortiGuard Labs.

Comments

Popular posts from this blog

LIVE Webinar on Zerologon Vulnerability Is Going To Take Place: Technical Analysis and Detection

  I'm sure most of you have now heard of a high-risk Windows server - called Zerologon - that would allow hackers to take over business networks completely. For those of you who don't know, in short, all supported versions of Windows Server applications are at risk of a serious patent infringement that resides in the Netlogon Remote Control Protocol for Domain Controllers. In other words, the primary vulnerability (CVE-2020-1472) can be exploited by the attacker to stop Active Directory services, and ultimately, the Windows domain without the need for authentication. What’s worse is that the exploitation of evidence of this error was released to the public last week, and soon after that, the attackers began exploiting vulnerabilities through programs that were not included in the wild. As explained in our compilation based on technical analysis published by Cynet's security analysts, the main problem is Microsoft's implementation of AES-CFB8, where it failed to use the ...

10 WAYS TO PROMOTE AND IMPROVE YOUR WEBSITE TRAFFIC

WEBSITE MEASUREMENT   Web traffic is measured to see the popularity of websites and personal pages or sections within a website. This is an automatically generated list of all pages that appear in the Traffic Statistics web file. The hit is generated when the file is provided. The page is considered a file, but the images are also files, so a page with 5 images can generate 6 hits (5 images and even a page). Page view is generated when a visitor requests any page on the website - the visitor always generates at least one page view (main page), but can create more. Track traffic can be recorded by inserting a small HTML code on each page of the website by tracking the external applications of the website. [2] Web traffic is sometimes measured by sniffing packets and thus random samples of traffic data are obtained, providing complete information about web traffic throughout Internet usage. The following types of information are often found when monitoring web traffic: [3]  ...

Sonos sues Google for infringing 5 more non-wire A.K.A Wireless audio patents

 Sonos has filed another patent lawsuit against Google, alleging that giant search infringes five wireless patents across the Nest and Chromecast product line. The move comes on the eve of Google's hardware hardware event on September 30, with the announcement of the Chromecast and Nest smart speaker and new Pixel phones. Sonos filed its first patent lawsuit against Google in January in a California court and the International Trade Commission; The state lawsuit was suspended while the ITC reached a decision on whether to block Google products that allegedly violated market rules. The new lawsuit was filed only in a federal court in the Western District of Texas - a recent patent for a patent case - and it represents an aggressive approach from Sonos. "We think it's important to show the depth and breadth of Google's copy," said Eddie Lazarus, a law officer at Sonos. "We showed them the 100 patent charts which we said were infringing, all to no avail." G...