Bionic Posted April 4, 2019 Posted April 4, 2019 https://www.bbc.co.uk/news/education-47805451 "A test of UK university defences against cyber-attacks found that in every case hackers were able to obtain "high-value" data within two hours." I wonder if primary/secondary schools would fair any better when it comes to penetration testing of IT networks.
bald_pig Posted April 4, 2019 Posted April 4, 2019 Unsurprisingly, spear phishing was responsible for a large proportion of the attacks. You can have the best defenses in the world, but the biggest risk is always the squishies, they're a lot harder to update and improve! 1
elsiegee40 Posted April 4, 2019 Posted April 4, 2019 I can’t help wondering if some of the blue/green button activity that’s being discussed in the Phishing thread by @FishCustard, etc was started by these “ethical hackers”
hardtailstar Posted April 4, 2019 Posted April 4, 2019 squishies Stealing, sounds much more polite than some descriptions!
FishCustard Posted April 4, 2019 Posted April 4, 2019 I can’t help wondering if some of the blue/green button activity that’s being discussed in the Phishing thread by @FishCustard, etc was started by these “ethical hackers” At first glance I would say "unlikely", given that it seems those ones are coming from spammers. I doubt JISC would have authorised such a scattergun campaign either.
synaesthesia Posted April 4, 2019 Posted April 4, 2019 "Cyber-defences" sounds like something from a crap 80's SciFi flick. However it should include the squishies instead of just being something people instantly think of as firewalls, AV etc.
elsiegee40 Posted April 4, 2019 Posted April 4, 2019 "Cyber-defences" sounds like something from a crap 80's SciFi flick. However it should include the squishies instead of just being something people instantly think of as firewalls, AV etc. Some of it did seem to be targeting O365 logins rather than bitcoin payments though.
TechMonkey Posted April 4, 2019 Posted April 4, 2019 "Cyber-defences" sounds like something from a crap 80's SciFi flick. I now have an image of a pixelated defence force in neon camo, running around trying to defend a firewall from space invader enemies, shooting lasers and throwing packets, ala Tron.
synaesthesia Posted April 4, 2019 Posted April 4, 2019 I now have an image of a pixelated defence force in neon camo, running around trying to defend a firewall from space invader enemies, shooting lasers and throwing packets, ala Tron. This makes a packet flood sound very dangerous!
bald_pig Posted April 4, 2019 Posted April 4, 2019 I now have an image of a pixelated defence force in neon camo, running around trying to defend a firewall from space invader enemies, shooting lasers and throwing packets, ala Tron. There was nothing pixelated in Tron, you've managed to imagine a worse version!
TechMonkey Posted April 4, 2019 Posted April 4, 2019 Only the data discs were stolen from Tron, the pixelated minions are all my own imagining.
jthompson Posted April 4, 2019 Posted April 4, 2019 Not read the details, but speed ought not to be interpreted as ease. What might take the likes of Fancy Bear all of 5 minutes might essentially be impossible for 99.999% of other people. The speed is probably less important than the means.
mavhc Posted April 4, 2019 Posted April 4, 2019 Harder problem for universities, can't really limit what programs can run as they're writing programs all the time. Have to go with "assume we've been hacked, limit what a hacker can access", stop escalation, limit access to data to minimum required. Keep personal data on a completely different system
Asgard Posted April 4, 2019 Posted April 4, 2019 (edited) I’m on one of the JISC security forums and it’s been the main topic of conversation today; JISC themselves replied to us all on the list. “ Good morning all, With regard to the article in the news today. These reports represent a sensationalised take on a serious policy paper that was unfortunately not linked-to in the BBC article. The paper is a high-level overview of well-known threats to the education sector and has sought to bring together a number of themes already widely reported. The main focus of the paper was that cyber risk is a Board responsibility informed by, but not driven by IT. The press release sought to highlight the importance of training and awareness strategies for all staff, as echoed in the cyber security assessment survey which lists phishing as the number one threat faced by the education and research sectors. The policy paper can be found at https://www.hepi.ac.uk/wp-content/uploads/2019/03/Policy-Note-12-Paper-April-2019-How-safe-is-your-data.pdf Regards “ If the policy paper was linked to the article it would of cast an entirely different light on the situation ... but hey at least it’s not more talk of the B word [emoji848] Edited April 4, 2019 by Asgard 2
mavhc Posted April 5, 2019 Posted April 5, 2019 What are their recommendations as to network security design, assuming you'll always find one person to give away their password, how do you still secure the data/network?
bald_pig Posted April 5, 2019 Posted April 5, 2019 What are their recommendations as to network security design, assuming you'll always find one person to give away their password, how do you still secure the data/network? Only use OAuth, obviously.
synaesthesia Posted April 5, 2019 Posted April 5, 2019 You can't design around it any differently to any other form of defence; it's going to be entirely around mitigation and ensuring people only have access to what they need. That doesn't help much when you're talking higher end staff with access to everything else, but then that's where MFA comes in, 2nd level encryption of confidential documents etc. For instance although a domain admin will be able to access our head teachers documents, emails etc, HR documents it will be necessary for them to have additional security for those areas; typically file level encryption.
mavhc Posted April 5, 2019 Posted April 5, 2019 Only use OAuth, obviously. Goes without saying, having another password database would be terrible, people would just use the same password, now there's twice as much chance of it leaking.
KD1987 Posted May 2, 2019 Posted May 2, 2019 Sadly a very large number of education establishments have been targeted recently that are running office 365 and using limited, or low cost (cough free) AV solutions that have not been sufficient to stop these kinds of next gen attacks. The Main reason this has got through is because of budgets. Many schools have scaled back their security offering and spend on these solutions to try and save on cost which has lead to a greater number of breaches and malware outbreaks from spam and Phishing attacks. Often the case is to justify the cost of migrating to 365 and cloud services the AV firewall and mail filtering solutions have been dropped to sign off these projects leading to these attacks getting through the sites defense. Also with GDPR a lot more schools and Colleges are now having to report the breaches which wasn't being done previously.
mavhc Posted May 3, 2019 Posted May 3, 2019 Mail filtering is easy, just convert everything to plain text, universities should be at a scale where they can make their own s/mime certs too. Is paid AV better than free AV? Aren't cloud services supposed to save money?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now