http://ift.tt/eA8V8J
As cars become more like computers, cybercriminals will have more ways to get into their important systems.
June 08, 2017 at 12:13AM
from By NICOLE PERLROTH
Twenty Practical Steps to Better Corporate Governance | The Corporate Secretaries International Association (CSIA) Please click the li...
http://ift.tt/eA8V8J
As cars become more like computers, cybercriminals will have more ways to get into their important systems.
June 08, 2017 at 12:13AM
from By NICOLE PERLROTH
http://ift.tt/eA8V8J
As more of our lives go online, online attackers are finding increasingly creative ways to wreak havoc using ransomware, and now, pyramid schemes.
June 07, 2017 at 05:13AM
from By SHEERA FRENKEL
This post is authored by Alex Weinert from the Identity Division’s Security and Protection Team.
Hey there!
I want to share three basic hygiene tips for account protection that every organization should consider. Applying these will go a long way in making sure that only the right users get into to their accounts (and all the things those accounts give access to). While there are many great security features available from Microsoft and our partners, in this blog post I am going to focus on three basic hygiene account security tasks:
While these don’t guarantee you’ll never deal with account compromises, we find that in most cases implementing these simple practices would have prevented attackers from getting initial intrusion. For account security, it really is true that “an ounce of prevention is worth a pound of cure.” So here is your “ounce of prevention.”
In a perfect world, no one would ever complete a multi-factor challenge. We would get rid of static rules (“MFA always”) which cause user friction, and replace them with perfect risk detection. Good users would never see MFA challenges – we’d always figure out we were working with a trusted person – and bad guys would never be able to solve them.
Alas, despite many years of hard work on the problem (and substantial improvements), we still have “false positives,” where the system detects risk on a login that belongs to a good user. This could be because
These are simple examples, but this “grey area” will exist even as our detection gets more sophisticated, because, unfortunately, the bad guys are evolving too. It is their job – through phishing, malware, and the use of botnets – to act more and more like the people whose accounts they are trying to hack. Because of that, we must be able to challenge when we aren’t sure they are good – and that will mean some false positives that challenge good users.
If your users aren’t set up for multi-factor authentication, then your security policy will effectively block them from signing in and doing their jobs. Now, good security enables better productivity, but when organizations (and individual users) are faced with the choice between security and productivity, they choose productivity. MFA readiness allows users to solve the occasional challenge from a false positive, which in turn allows you to have a great security posture. That is why a good MFA registration policy is first on our list for basic hygiene.
In Azure Active Directory, you can use Azure AD Identity Protection to set up a policy to cover your users for MFA registration. Azure AD MFA will allow MFA challenges using voice, SMS, push-notification, or OAUTH token challenges. The registration policy will offer whatever you have configured in Azure AD MFA.
To set up a registration policy with Azure AD Identity Protection, just look at the menu on the left, and under “Configure” choose “Multi-factor authentication registration”.
Once you do this, you can choose the users to include in the policy, see the current state of MFA registration in your organization, and enable the policy.
Now, when a user who hasn’t yet registered for MFA logs in, they will see this:
This process has a few major benefits:
Ok, now that everyone is registered, let’s put all this MFA goodness to work.
There are many tools out there for telling you when a login has gone wrong, and a bad guy got in to your resources by pretending to be a good user. While helpful for forensics and improving your security posture for future events, the second step in your “Basic Hygiene” is to prevent bad guys from logging in at all. Azure Active Directory Identity Protection can detect risky logins in real time. Examples are logins from TOR browsers, new or impossible locations, or Botnet infected devices. To see the events impacting your organization, check the “Risk Events” area in Azure AD Identity Protection.
An unfortunate reality is that password leaks are happening daily (the biggest recorded breach was reported last week, at over 1B cred pairs), and 60% of people reuse their usernames and passwords. We detect and block tens of millions of credential replay attacks every day.
Our detection algorithms are based on our experience defending Microsoft’s consumer and enterprise assets, and the assets of our customers. They benefit from the supervised machine learning system which processes 20TB of data a day and self-adapts to new attack patterns, as well as many applied data scientists. Applying this evaluation to conditional access is your path to ensuring that bad actors are stopped in their tracks. That’s where Azure AD Conditional Access comes in. Azure AD Conditional Access is your Swiss army knife for making sure all logins are secure and compliant. It allows you to specify conditions of a login which impose more requirements before a resource can be accessed. With login risk assessment, you can apply a policy to challenge risky logins. Pick “Sign-in Risk Policy” and enable the policy.
With this policy enabled, you can apply a real-time intercept when risk is detected. The end user experience is as follows:
If a bad guy logs in (in this case, emulated from TOR):
The mobile app then gets the approval notification:
And the user simply doesn’t approve (or, if it *is* the good user, can get in), with the same approval process as previously described.
Users regularly fall for phishing scams, get malware, reuse their credentials on other systems, and use easily guessed passwords. As a result, we see a lot of cases where we are confident that the valid user is not the only one in possession of their password.
If we are seeing a lot of attempted logins or bad activity in a login, or find your users’ credentials leaked on the black market, we notify you of this by setting the “User Risk” score, indicating a probability that the user’s password is known to a bad actor. You can see which users the system is detecting as “At Risk” and why in Azure AD Identity Protection under “Users flagged for risk”. Notice my account about mid-way down on the right is marked as being at medium risk with six events.
(Please note that for hybrid environment, our ability to detect leaked credentials from black market finds requires that you have enabled password hash sync from your on-premises environment to Azure AD.)
I am frequently asked if compromise of the password is significant if the user is configured for MFA – the answer is emphatically yes! Multi-factor authentication is multi-factor if it utilizes at least two different mechanisms (choosing from a secret you know, what you have, and what you are). If the password is compromised, then you really don’t have a valid secret anymore. So, once we detect a compromised credential, it is important to lock out that user until the credential can be remediated, or better, we can have the user change the password themselves as soon as they can do so safely (with MFA). We do this on our consumer (Microsoft account) side, and find that we can get the user to safely change their password before the bad guys have a chance to act about 80% of the time. Our investigations in the enterprise cases show roughly the same results in terms of stopping attacks even when the password is known to the attacker.
Here again, Azure AD Conditional Access is your friend. When the condition includes users at risk of compromised credentials, we can challenge for MFA and require a password change. Look for “User Risk Policy”. In this case, I have configured the policy to require password change when user credential risk is medium or above. For this to work, you need to be mastering your passwords in the cloud, so if you are in a hybrid deployment, be sure password writeback is enabled!
When a user logs in with a user risk score that triggers this policy, they see the following:
On clicking next, they are asked to do multi-factor authentication:
And upon approving the login, the user can change their password.
And importantly – they can carry on with their work! Which emphasizes again the importance of getting those users registered!
So, there you have it! Three easy steps to VASTLY better account protection by doing basic hygiene! In summary:
Azure Active Directory makes it easy!
Be safe!
Alex (@alex_t_weinert)
June 05, 2017 at 09:37PM
from Microsoft Secure Blog Staff
http://ift.tt/eA8V8J
President Vladimir V. Putin of Russia said on Thursday that it’s possible Russian hackers may have independently staged cyber attacks against countries with strained relations with Moscow, but that the Russian state had never been involved.
June 02, 2017 at 12:52AM
from By REUTERS
http://ift.tt/eA8V8J
The Times’s new cybersecurity reporter explains why the prospect of self-driving cars strikes fear in the hearts of security reearchers.
May 27, 2017 at 06:38PM
from By FARHAD MANJOO and SHEERA FRENKEL
http://ift.tt/eA8V8J
The president’s grown two sons, who run the company, met with agents; Eric Trump said there had been no successful intrusion into the computer system.
May 27, 2017 at 05:34AM
from By WILLIAM K. RASHBAUM
http://ift.tt/eA8V8J
The president’s grown two sons, who run the company, met with agents; Eric Trump said there had been no successful intrusion into the computer system.
May 27, 2017 at 05:34AM
from By WILLIAM K. RASHBAUM
http://ift.tt/eA8V8J
The agreement, which includes the District of Columbia, ends an investigation into how hackers obtained information about tens of millions of people in 2013.
May 24, 2017 at 04:29AM
from By RACHEL ABRAMS
http://ift.tt/eA8V8J
Since the 1980s, North Korea has been known to train cadres of digital soldiers to engage in electronic warfare. Now this force is under scrutiny.
May 17, 2017 at 01:17AM
from By CHOE SANG-HUN and PAUL MOZUR
http://ift.tt/eA8V8J
Indicators are far from conclusive, but intelligence officials and private security experts say that North Korean-linked hackers are likely suspects in global ransomware attacks.
May 16, 2017 at 07:04AM
from By NICOLE PERLROTH and DAVID E. SANGER
http://ift.tt/eA8V8J
For years, the company has tried to change the perception that its software was vulnerable to hackers. A global cyberattack renewed those issues.
May 16, 2017 at 06:04AM
from By NICK WINGFIELD
http://ift.tt/eA8V8J
For years, the company has tried to change the perception that its software was vulnerable to hackers. A global cyberattack renewed those issues.
May 16, 2017 at 06:04AM
from By NICK WINGFIELD
http://ift.tt/eA8V8J
Some tips from computer security experts.
May 16, 2017 at 02:03AM
from By BRIAN X. CHEN
http://ift.tt/eA8V8J
Are last week’s cyberattacks proof that it’s time to go back to analog?
May 16, 2017 at 02:03AM
from By STEVEN WEBER and BETSY COOPER
http://ift.tt/eA8V8J
While foiling an attack on a military contractor, investigators watched Iranians use a tool that had also been deployed to compromise Ukraine’s power grid.
May 16, 2017 at 12:04AM
from By NICOLE PERLROTH
http://ift.tt/eA8V8J
A so-called ransomware attack struck computers around the world. Time to take those software updates seriously.
May 15, 2017 at 10:03PM
from By JIM KERSTETTER
http://ift.tt/eA8V8J
Students reported being locked out of final papers, while other people said A.T.M.s and the payment systems at gas stations had been affected.
May 15, 2017 at 12:02PM
from By GERRY MULLANY and PAUL MOZUR
http://ift.tt/eA8V8J
While cybercrimes like the global ransomware attack have much in common with traditional robberies, they can be more destructive and harder to solve.
May 15, 2017 at 06:00AM
from By KATRIN BENNHOLD and MARK SCOTT
http://ift.tt/eA8V8J
While cybercrimes like the global ransomware attack have much in common with traditional robberies, they can be more destructive and harder to solve.
May 15, 2017 at 06:00AM
from By KATRIN BENNHOLD and MARK SCOTT
http://ift.tt/eA8V8J
Vietnam is a case in point, with a group that targets foreign companies appearing to be sponsored by the state, according to a new report.
May 15, 2017 at 04:00AM
from By MIKE IVES and PAUL MOZUR