Thursday, February 4, 2016

Israel's Cyber Sector Blooms In The Desert

BEERSHEBA, ISRAEL:  A modern metropolis rising from Israel's Negev desert stands on the frontline of a global war against hacking and cyber-crime, fulfilling an ambition of the country's founding father.

David Ben Gurion famously said he wanted to make the Negev bloom.

Today, in the streets of Beersheba, a city of 200,000, his dream is taking shape in a form he likely did not anticipate.

Long a poor relation of hyper-modern Tel Aviv, Beersheba has traditionally been a refuge for poor, working class and Sephardic Jews of Middle Eastern descent.

But the city in the vast Negev desert of southern Israel has experienced a rapid gentrification since the start of the decade, during which middle class neighbourhoods have expanded.

The real estate boom in Beersheba has been fuelled by the city's ambition to be Israel's cyber capital, especially since the creation of its industrial park CyberSpark.

Two ultra-modern complexes house a dozen Israeli companies, start-ups, venture capital funds and foreign groups such as Lockheed Martin, Deutsche Telekom, Oracle and IBM.

Already, 1,500 technicians, engineers and researchers are hard at work.

Many have been trained in the computer sciences department of the local Ben Gurion University part of a planned symbiosis between the university and the company, which are linked by pedestrian bridges.

"We have established a perfect ecosystem with the integration of Israeli companies and foreign multinationals, the university and the foundation of the Israeli army specialised in cybersecurity, which will move from the region of Tel Aviv to Beersheba," said Tom Ahi Dror, CyberSpark project leader at the Israeli National Cyber Bureau.

Starting From Scratch

Israeli Prime Minister Benjamin Netanyahu has spoken highly of the development, saying the close proximity allows "a physical interaction between security officials, academia and industry, in Israel and abroad".

"They meet, they talk and they create together," he told a "CyberTech" conference in Tel Aviv, calling cyber security "vital" for a small country like Israel, which is faced with multiple threats and a favourite target of hackers.

According to a study carried out in 2012, Israel "may be the most heavily targeted country in the world, by hostile hackers, nonstate actors, and states, with as many as a thousand web attacks per minute".

Tal Elal, deputy mayor of the city, pinpoints the secret of CyberSpark's success: "We started from scratch four years ago and we designed a customised project to meet the exact needs of companies specialising in cybersecurity."

Two more complexes comprising 27 buildings are to be added, and the municipality expects the population to grow by 100,000 in the next 10 years.

About 30,000 soldiers, including 7,000 career officers, will move in the coming years to bases and a technology campus to be built on 100 hectares (250 acres) near CyberSpark and around Beersheba.

As a lure from the bustle of cosmopolitan Tel Aviv, the government plans a bonus of $18,000 for single officers and $50,000 for families who spend at least five years in Beersheba.

Cyber Security's Future

"We will do everything to integrate this population and avoid creating ghettoes where officers live, as has been the case in the past in other places," Elal said.

For the private sector, the government is also offering subsidies equivalent to 20 percent of salaries for three years to company employees who settled in Beersheba.

The state hopes to expand a sector which already has 250 companies of all sizes, Israeli and foreign, in the country.

Last year, the sector's exports reached a record $3.5 billion, according to government figures.

"Israel represents only 0.1 percent of the world's population but 20 percent of global investments (in cyber security)," said Dror.

"Cyber security has a very bright future," said Dudu Mimran, head of a Deutsche Telekom innovation laboratory based in Beersheba.

"It is an endless race in which hackers are always one step ahead because it is they who take the initiative," he added.

"And it is then up to us to respond to protect businesses, governments and individuals."

Israel's Cyber Sector Blooms In The Desert

BEERSHEBA, ISRAEL:  A modern metropolis rising from Israel's Negev desert stands on the frontline of a global war against hacking and cyber-crime, fulfilling an ambition of the country's founding father.

David Ben Gurion famously said he wanted to make the Negev bloom.

Today, in the streets of Beersheba, a city of 200,000, his dream is taking shape in a form he likely did not anticipate.

Long a poor relation of hyper-modern Tel Aviv, Beersheba has traditionally been a refuge for poor, working class and Sephardic Jews of Middle Eastern descent.

But the city in the vast Negev desert of southern Israel has experienced a rapid gentrification since the start of the decade, during which middle class neighbourhoods have expanded.

The real estate boom in Beersheba has been fuelled by the city's ambition to be Israel's cyber capital, especially since the creation of its industrial park CyberSpark.

Two ultra-modern complexes house a dozen Israeli companies, start-ups, venture capital funds and foreign groups such as Lockheed Martin, Deutsche Telekom, Oracle and IBM.

Already, 1,500 technicians, engineers and researchers are hard at work.

Many have been trained in the computer sciences department of the local Ben Gurion University part of a planned symbiosis between the university and the company, which are linked by pedestrian bridges.

"We have established a perfect ecosystem with the integration of Israeli companies and foreign multinationals, the university and the foundation of the Israeli army specialised in cybersecurity, which will move from the region of Tel Aviv to Beersheba," said Tom Ahi Dror, CyberSpark project leader at the Israeli National Cyber Bureau.

Starting From Scratch

Israeli Prime Minister Benjamin Netanyahu has spoken highly of the development, saying the close proximity allows "a physical interaction between security officials, academia and industry, in Israel and abroad".

"They meet, they talk and they create together," he told a "CyberTech" conference in Tel Aviv, calling cyber security "vital" for a small country like Israel, which is faced with multiple threats and a favourite target of hackers.

According to a study carried out in 2012, Israel "may be the most heavily targeted country in the world, by hostile hackers, nonstate actors, and states, with as many as a thousand web attacks per minute".

Tal Elal, deputy mayor of the city, pinpoints the secret of CyberSpark's success: "We started from scratch four years ago and we designed a customised project to meet the exact needs of companies specialising in cybersecurity."

Two more complexes comprising 27 buildings are to be added, and the municipality expects the population to grow by 100,000 in the next 10 years.

About 30,000 soldiers, including 7,000 career officers, will move in the coming years to bases and a technology campus to be built on 100 hectares (250 acres) near CyberSpark and around Beersheba.

As a lure from the bustle of cosmopolitan Tel Aviv, the government plans a bonus of $18,000 for single officers and $50,000 for families who spend at least five years in Beersheba.

Cyber Security's Future

"We will do everything to integrate this population and avoid creating ghettoes where officers live, as has been the case in the past in other places," Elal said.

For the private sector, the government is also offering subsidies equivalent to 20 percent of salaries for three years to company employees who settled in Beersheba.

The state hopes to expand a sector which already has 250 companies of all sizes, Israeli and foreign, in the country.

Last year, the sector's exports reached a record $3.5 billion, according to government figures.

"Israel represents only 0.1 percent of the world's population but 20 percent of global investments (in cyber security)," said Dror.

"Cyber security has a very bright future," said Dudu Mimran, head of a Deutsche Telekom innovation laboratory based in Beersheba.

"It is an endless race in which hackers are always one step ahead because it is they who take the initiative," he added.

"And it is then up to us to respond to protect businesses, governments and individuals."

Israel's Cyber Sector Blooms In The Desert

BEERSHEBA, ISRAEL:  A modern metropolis rising from Israel's Negev desert stands on the frontline of a global war against hacking and cyber-crime, fulfilling an ambition of the country's founding father.

David Ben Gurion famously said he wanted to make the Negev bloom.

Today, in the streets of Beersheba, a city of 200,000, his dream is taking shape in a form he likely did not anticipate.

Long a poor relation of hyper-modern Tel Aviv, Beersheba has traditionally been a refuge for poor, working class and Sephardic Jews of Middle Eastern descent.

But the city in the vast Negev desert of southern Israel has experienced a rapid gentrification since the start of the decade, during which middle class neighbourhoods have expanded.

The real estate boom in Beersheba has been fuelled by the city's ambition to be Israel's cyber capital, especially since the creation of its industrial park CyberSpark.

Two ultra-modern complexes house a dozen Israeli companies, start-ups, venture capital funds and foreign groups such as Lockheed Martin, Deutsche Telekom, Oracle and IBM.

Already, 1,500 technicians, engineers and researchers are hard at work.

Many have been trained in the computer sciences department of the local Ben Gurion University part of a planned symbiosis between the university and the company, which are linked by pedestrian bridges.

"We have established a perfect ecosystem with the integration of Israeli companies and foreign multinationals, the university and the foundation of the Israeli army specialised in cybersecurity, which will move from the region of Tel Aviv to Beersheba," said Tom Ahi Dror, CyberSpark project leader at the Israeli National Cyber Bureau.

Starting From Scratch

Israeli Prime Minister Benjamin Netanyahu has spoken highly of the development, saying the close proximity allows "a physical interaction between security officials, academia and industry, in Israel and abroad".

"They meet, they talk and they create together," he told a "CyberTech" conference in Tel Aviv, calling cyber security "vital" for a small country like Israel, which is faced with multiple threats and a favourite target of hackers.

According to a study carried out in 2012, Israel "may be the most heavily targeted country in the world, by hostile hackers, nonstate actors, and states, with as many as a thousand web attacks per minute".

Tal Elal, deputy mayor of the city, pinpoints the secret of CyberSpark's success: "We started from scratch four years ago and we designed a customised project to meet the exact needs of companies specialising in cybersecurity."

Two more complexes comprising 27 buildings are to be added, and the municipality expects the population to grow by 100,000 in the next 10 years.

About 30,000 soldiers, including 7,000 career officers, will move in the coming years to bases and a technology campus to be built on 100 hectares (250 acres) near CyberSpark and around Beersheba.

As a lure from the bustle of cosmopolitan Tel Aviv, the government plans a bonus of $18,000 for single officers and $50,000 for families who spend at least five years in Beersheba.

Cyber Security's Future

"We will do everything to integrate this population and avoid creating ghettoes where officers live, as has been the case in the past in other places," Elal said.

For the private sector, the government is also offering subsidies equivalent to 20 percent of salaries for three years to company employees who settled in Beersheba.

The state hopes to expand a sector which already has 250 companies of all sizes, Israeli and foreign, in the country.

Last year, the sector's exports reached a record $3.5 billion, according to government figures.

"Israel represents only 0.1 percent of the world's population but 20 percent of global investments (in cyber security)," said Dror.

"Cyber security has a very bright future," said Dudu Mimran, head of a Deutsche Telekom innovation laboratory based in Beersheba.

"It is an endless race in which hackers are always one step ahead because it is they who take the initiative," he added.

"And it is then up to us to respond to protect businesses, governments and individuals."

Israel's Cyber Sector Blooms In The Desert

BEERSHEBA, ISRAEL:  A modern metropolis rising from Israel's Negev desert stands on the frontline of a global war against hacking and cyber-crime, fulfilling an ambition of the country's founding father.

David Ben Gurion famously said he wanted to make the Negev bloom.

Today, in the streets of Beersheba, a city of 200,000, his dream is taking shape in a form he likely did not anticipate.

Long a poor relation of hyper-modern Tel Aviv, Beersheba has traditionally been a refuge for poor, working class and Sephardic Jews of Middle Eastern descent.

But the city in the vast Negev desert of southern Israel has experienced a rapid gentrification since the start of the decade, during which middle class neighbourhoods have expanded.

The real estate boom in Beersheba has been fuelled by the city's ambition to be Israel's cyber capital, especially since the creation of its industrial park CyberSpark.

Two ultra-modern complexes house a dozen Israeli companies, start-ups, venture capital funds and foreign groups such as Lockheed Martin, Deutsche Telekom, Oracle and IBM.

Already, 1,500 technicians, engineers and researchers are hard at work.

Many have been trained in the computer sciences department of the local Ben Gurion University part of a planned symbiosis between the university and the company, which are linked by pedestrian bridges.

"We have established a perfect ecosystem with the integration of Israeli companies and foreign multinationals, the university and the foundation of the Israeli army specialised in cybersecurity, which will move from the region of Tel Aviv to Beersheba," said Tom Ahi Dror, CyberSpark project leader at the Israeli National Cyber Bureau.

Starting From Scratch

Israeli Prime Minister Benjamin Netanyahu has spoken highly of the development, saying the close proximity allows "a physical interaction between security officials, academia and industry, in Israel and abroad".

"They meet, they talk and they create together," he told a "CyberTech" conference in Tel Aviv, calling cyber security "vital" for a small country like Israel, which is faced with multiple threats and a favourite target of hackers.

According to a study carried out in 2012, Israel "may be the most heavily targeted country in the world, by hostile hackers, nonstate actors, and states, with as many as a thousand web attacks per minute".

Tal Elal, deputy mayor of the city, pinpoints the secret of CyberSpark's success: "We started from scratch four years ago and we designed a customised project to meet the exact needs of companies specialising in cybersecurity."

Two more complexes comprising 27 buildings are to be added, and the municipality expects the population to grow by 100,000 in the next 10 years.

About 30,000 soldiers, including 7,000 career officers, will move in the coming years to bases and a technology campus to be built on 100 hectares (250 acres) near CyberSpark and around Beersheba.

As a lure from the bustle of cosmopolitan Tel Aviv, the government plans a bonus of $18,000 for single officers and $50,000 for families who spend at least five years in Beersheba.

Cyber Security's Future

"We will do everything to integrate this population and avoid creating ghettoes where officers live, as has been the case in the past in other places," Elal said.

For the private sector, the government is also offering subsidies equivalent to 20 percent of salaries for three years to company employees who settled in Beersheba.

The state hopes to expand a sector which already has 250 companies of all sizes, Israeli and foreign, in the country.

Last year, the sector's exports reached a record $3.5 billion, according to government figures.

"Israel represents only 0.1 percent of the world's population but 20 percent of global investments (in cyber security)," said Dror.

"Cyber security has a very bright future," said Dudu Mimran, head of a Deutsche Telekom innovation laboratory based in Beersheba.

"It is an endless race in which hackers are always one step ahead because it is they who take the initiative," he added.

"And it is then up to us to respond to protect businesses, governments and individuals."

Self-Driving Car Technology Poses High Hacking Risk: Study

While major auto companies are working on introducing the futuristic self-driving technology in cars soon, this threatens to open new security problems for them as hackers have sensed an opportunity here, a researcher has predicted.
"We are a long way from securing the non-autonomous vehicles, let alone the autonomous ones," said Stefan Savage, computer science professor at the University of California-San Diago, in MIT Technology Review.
Pointing out security flaws to car companies which are into driverless car technology, the researcher said that extra computers, sensors and improved Internet connectivity required to make a car drive on its own increase the possible weak points.
Tech giant Google is working on autonomous cars as part of Google X project to develop technology for mainly electronic cars. The software installed in Google's cars is called Google Chauffeur.
Recently, with the help from Nasa space technology, automaker Nissan successfully test-drove its all-electric, driverless car at Nasa's Ames Research Centre in California.
Swedish automobile giant Volvo is also developing intelligent high bandwidth streaming capabilities in collaboration with Ericsson's cloud expertise and network to create a highway full of autonomous cars.
Tesla Motors, an American automotive and energy storage company, is also serious about self-driving car tech and hired processor design veteran Jim Keller to lead its autopilot hardware engineering team.
How does this technology work? The self-driving cars, or prototypes, rely on sensors to determine the surroundings and objects like pedestrians, cyclists and other vehicles around it.
The software assisting the sensors then decides the speed and trajectory to drive safely.
How is this technology a threat to security? Savage said that it is possible to take control of conventional vehicles in various ways, for example by dialling into a car's built-in cellular connection or by giving a driver a music CD that makes the car connect to an attacker's computer.
Once inside the system, the hackers can take control of the brakes, engine or other components of a person's car remotely.
The developers are still not able to isolate these "important" parts of the car because everything must be connected to enable many functions people expect of cars.
This is also owing to the fact that carmakers do not know exactly what software is inside the vehicles they sell because the third-party suppliers guard the details of the software inside, things like the brake-control system or central locking components.

Friday, August 14, 2015

Super-Scary Android Flaw Found

Stagefright, which processes several popular media formats, is implemented in native code -- C++ -- which is more prone to memory corruption than memory-safe languages such as Java, according to Zimperium.
Stagefright has several remote code execution vulnerabilities that can be exploited using various methods, Zimperium said.
The worst of them doesn't require any user interaction.
The vulnerabilities critically expose 95 percent of Android devices -- about 950 million, by Zimperium's count.
"Users of Android versions older than 4.1 are at extreme risk," Drake told LinuxInsider.

The No-Touch Flaw

Attackers need nothing more than a victim's mobile phone number to exploit the most dangerous Stagefright flaw, Zimperium said.
They can send a specially crafted media file delivered as an MMS message.
A fully weaponized, successful attack could delete the message before the user sees it, leaving only a notification that the message was received.
The victim wouldn't need to take any action for the attack to be successful.
Zimperium reported the vulnerability to Google and submitted patches, which Google applied within 48 hours.

Who's Safe

Users of SilentCircle's Blackphone have been protected against these problems with the release earlier this month of PrivateOS version 1.1.7, Zimperium reported, and Mozilla's Firefox for mobile, aka "Fennec," includes fixes for these issues in v38 and later versions.
Google is coordinating with members of the Open Handset Alliance to get the issues addressed in official Android-compatible devices.
"We thank Joshua Drake for his contributions," said Google spokesperson Elizabeth Markman. "The security of Android users is extremely important to us, and so we responded quickly -- and patches have already been provided to partners that can be applied to any device."

What's Happening Now

If you're an Android device user, expect nothing and prepare for trouble.
"Many carriers and manufacturers prefer to push patches out to customers themselves, if at all," said Ken Westin, security analyst for Tripwire.
That means "even well after the patches are made public, more than half [of users] will still be vulnerable," he told LinuxInsider.
Further, this vulnerability goes back to Android 2.2, which was released five years ago, Westin pointed out, so "some of these devices may not have patches available through their carriers as they are too old and are no longer supported."
"This problem doesn't show any signs of going away," Drake said. "Even Nexus devices remain without a patch today, presumably because of this very problem."
Tripwire so far has not seen any exploits of the Stagefright flaw in the wild, although "this can change very quickly now that the vulnerability has been exposed," Westin said.

Android's General Safety Overview

Most Android devices, including all newer devices, "have multiple technologies that are designed to make exploitation more difficult," Google's Markman told LinuxInsider. Android devices "also include an application sandbox designed to protect user data and other applications on the device."
However, the jury's still out on whether sandboxes can fully protect devices.
Bluebox last year discovered an Android design error it dubbed "Fake ID," which let malware sneak by Android's app sandbox and take control of other apps.
Google removed the Android webview Flash flaw from Android 4.4 KitKat, but 82 percent of devices couldn't update to the new version of the OS because mobile carriers and manufacturers delayed or did not deliver the update, Bluebox said.
Sandboxes have failed to stop advanced cyberattacks, according to FireEye.

Staying Safe in the Malware Storm

Applying strong authentication to critical apps could help Android users remain safe, Secure Channels CEO Richard Blech told LinuxInsider. Also, login credentials should not be kept on the device.
"Always use a currently supported mobile device," Zimperium's Drake suggested, and "keep your device updated to the latest version at all times." If an update isn't available, "manually install an OS likeCyanogenMod that supports older devices for a longer period of time." 

Tuesday, August 11, 2015

heuristic

A heuristic is a commonsense guideline used to increase the probability of solving a problem by directing one's attention to things that are likely to matter. The word is derived from the Greek "heurisko" which simply means "I find". The exclamation "eureka", meaning "I found it!", shares roots with heuristic.

Just as the "Eureka!" screaming forty-niners of California's Gold Rush did not have secret knowledge or tools to tell them exactly where all the gold was buried; software testers don't know exactly where the bugs are going to hide. However, both software testers and gold miners know where bugs and gold have been found before. We can use that knowledge of past discoveries and the nature of what we seek to create heuristics that help us narrow in on areas most likely to contain the treasure.

Gold miners and testers can find treasure by accident. However, intentional exploration for bugs and gold are more likely to produce results than aimless wandering. That last statement is a heuristic. It is true most of the time, but sometimes it can be proven false. Sometimes wandering testers and miners stumble into something very important. I just don't want to do all my testing by accident.
Heuristic-based testing may not give us concrete answers, but it can guide us to the important things to test. Heuristics can also be used in automation to provide information to guide human testers.
There was a time that I told developers and project managers that I could not test their products when the requirements did not include straightforward "testable" criteria. I thought that I could not test without being able to report "pass" or "fail" for each test.
A good example was a requirement that stated something like "the user shall not have to wait an unacceptable amount of time". As a good quality school tester working in a factory school organization, I demanded to know how long was acceptable before I could start testing. I wanted to quantify "unacceptable". In this case, the truth is that "unacceptable" will vary based on the user. There were no contractual SLAs to satisfy. I may not be able to report that the requirement is met, but I can provide useful information to the project team to assist in determining if the performance is acceptable.
I have since learned that answers to heuristic questions are useful. It was in that same project that I started applying heuristics to automated data validation. Even without concrete requirements, we testers can provide provide information that is useful in answering important testing questions -- especially the qualitative questions. (As a side note, I am now amazed at how much we who call ourselves "Quality Assurance" like to focus on quantitative requirements and metrics.)
To use heuristics in testing, create a list of open-ended questions and guidelines. This will not be a pass/fail list of test criteria. It will not be a list of specific test steps. Instead it can be used to guide your test scripting and exploration for bugs. You will likely develop general heuristics that you can apply to all your testing and specific heuristics that apply to specific applications.
We need to be careful to apply heuristics as heuristics and not enforceable rules. For example, most people involved in testing web application have heard the heuristic that every page should be within three clicks of any other page. Applying this "rule" to web application design usually results in better usability. However, it does not always improve usability. Sometimes making every page within three clicks of another is not reasonable. Adding too many links are likely to confuse users more than they help. (Another heuristic?) Complex work flows often require that pages be more than three clicks away from others. Common sense needs to be applied to heuristics to ensure they are applied only when they fit the context.
Happy bug prospecting.