Showing posts with label News Punch. Show all posts
Showing posts with label News Punch. Show all posts

Monday, March 23, 2015

સુપ્રીમ કોર્ટ નો ઐતિહાસિક નિર્ણય : IT એક્ટ માં 66A ગેરબંધારણીય

મિત્રો, IT એક્ટ-૨૦૦૦ વિષે આપને થોડોઘણો ખ્યાલ હશે જ જે વિવિધ પ્રકારના સાયબર ક્રાઈમ ને નિયંત્રિત કરવા માટે ભારત સરકાર દ્વારા અમલ માં છે . આજરોજ થી આ એક્ટ માં મહત્વનો ફેરફાર કરવામાં આવ્યો છે. 

સુપ્રીમ કોર્ટે આજે એક સીમાચિહ્ન ચૂકાદામાં કલમ 66A રદી કરી નાખી છે. આ ધારા અંતર્ગત કોમ્યુનિકેશન સર્વિસીસ સોશ્યલ મિડીયા જેવા કે ફેસબુક, ટ્વીટર, વ્હોટસ એપ પર અમુક પ્રકારના મેસેજ, વિડીયો કે તસવીરો પોસ્ટ કરવાને સજા પાત્ર ગુનો બનાવતી હતી. આ ધારાને આજે સર્વોચ્ચ અદાલતે રદ્દ કરી છે. કેમકે તે અભિવ્યક્તિના મૂળભૂત હકના વિરોધમાં હતી. 
કલમ 66એ આર્ટીકલ 192(2)ની બહાર છે, તેની હેઠળ સખત પગલાંને મંજૂર કરી શકાય નહી અને તેને સંપૂર્ણપણે નાબૂદ કરવામાં આવે છે. તેમજ જે ગેરબંધારણીય છે. આને પગલે હવે કોઇ પણ વ્યક્તિ ઇન્ટરનેટ,બ્લોગ,વ્હોટસેપ,ટ્વીટર ફેસબુક પર કરેલી કોઇ પણ ટિપ્પણી માટે ગુનેગાર ઠરશે નહી. આને આપણે વાણી સ્વાતંત્ર્ય નો હક તરીકે માની શકીએ. 
અત્રે ઉલ્લેખનીય છે કે તાજેતરમાં જ બરેલીના રહેવાસી વિદ્યાર્થી ગુલરેઝ ઉર્ફે વિક્કી ખાને યુપી સરકારના પ્રધાન આઝમ વિરુદ્ધ કોમેન્ટ કરી હતી. તેનાથી ધાર્મિક ઉન્માદ ફેલાવવાનો ખતરો હતો. વિદ્યાર્થીને 14 દિવસની જ્યુડિશિયલ કસ્ટડીમાં મોકલી દેવામાં આવ્યો હતો. પોતાને આઝમ ખાનના મીડિયા પ્રભારી ગણાવતા ફસાહત અલીએ વિક્કી સામે ફરિયાદ નોંધાવી હતી. 

તેની પહેલા વડોદરા માં પણ ફેસબુક પર ધાર્મિક લાગણી દુભાવતી કોઈ પોસ્ટ ને કરને કોમી તંગદીલી ના બનાવો બન્યા હોવાના કિસ્સા છે.
થોડા સમય પહેલા થાણેની બે યુવતીઓએ શિવસેનાના તે સમયના સુપ્રીમો બાળા સાહેબ ઠેકરે વિરુદ્ધ ઇન્ટરનેટ પર ટિપ્પણી કરી હતી તેમને જેલમાં પૂરી દેવાઇ હતી. સુપ્રીમના આ ચૂકાદાથી આ ગુન્હેગારોને રાહત મળી છે. 

એક રીતે જોવા જઈએ તો વાણી અને વિચારો નું સ્વાતંત્ર્ય જળવાય એના સમર્થન માં જ આ નિર્ણય લેવાયો છે અને મોટા ભાગના યુવાઓ, લેખકો , પત્રકારો બધા ને અમુક અંશે રાહત છે. પરંતુ આ રાહત માં પણ અમુક અંશે મર્યાદા જળવાઈ રહે તથા કોઈ ની વ્યક્તિગત કે ધાર્મિક લાગણી ને હાની ના પહોચે તે રીતના નિયંત્રણો મુકવા આવશ્યક છે. 



Wednesday, December 17, 2014

Nought attitude of major Indian Corporates to fight against fraud

Almost Indian corporate companies does not seem to be doing enough to tackle fraud, according to a recent survey.
A well known research organization Deloitte India have some statistics. 
  • 88% respondents felt a stringent regulatory environment could help reduce instances of fraud in the future 
  • 56% believed incidents of fraud would continue to rise over the next two years. 
  • 38%onlyrespondents indicate that they organize periodic training programs for senior management on fraud risk management.

    Only one-third respondents took legal action against any fraudster.

Findings reveal most respondents identifying two provisions in the company law the mandatory establishment of a vigil mechanism for listed companies, and greater accountability on board and directors to prevent and detect fraud - as key measures to fight fraud. Diversion or theft of funds or goods, bribery and corruption, and regulatory non-compliance are seen as the top three types of fraud experienced by corporate India over the past two years.
As a means to detect fraud, respondents indicate relying on 
  • internal audit reviews (62%), 
  • whistle blower hotlines (53%) and 
  • IT controls (51%). 
The report unveils that actions taken by corporates upon detection of fraud continue to remain conservative 

  • internal investigations (87% respondents), 
  • disciplinary action taken against the fraudster (78%) and 
  • update of existing controls (77%).

Most survey respondents did not contemplate the danger from emerging fraud risks, such as 
  • social media fraud (69%), 
  • eCommerce fraud (60%), 
  • cloud computing fraud (96%), and 
  • virtual-currency fraud (50%). 
Company executives cited leakage and data loss of confidential company information, fraudulent transactions through usage of stolen or hacked credit/debit card information and liabilities therein, and re-direction of payments to fraudulent accounts for purchase of goods, as among the key risks of doing business online.

Wednesday, April 23, 2014

Facebook will track your every movement with its new feature ‘Nearby Friends’


Facebook is the primary social networking service for billions of users worldwide. Its impact has been so huge that Oxford English Dictionary added a new meaning to the noun ‘friend’, “a contact on a social networking web site”, and the verbs ‘friend’ and ‘unfriend’ were also added. Thus, it is clear that it is a social networking site of choice for many. 

This internet-based social networking is about to take a location-based spin as Facebook announces that people will be able to track and find their friends if they are nearby using the new service called ‘Nearby Friends’. It will be soon available to US-based customers of Facebook’s native app on iPhone and Android. The service will be optional and users can turn it ‘off’ if they do not wish to share their location with their friends on Facebook.

Once you choose to use this feature than your friends or people in a list can see your GPS location if they are also using this service. For a defined time-period, users can also broadcast their location to specific friends. The options will be: less than 0.5 miles; 0.7 miles; and 1.8 miles. The friend can see the GPS location on a map. The service can be used in many ways for example to choose and meet at a geographical point, to recommend places of interest such as shops or restaurants or to guide someone on a new route.

“When you see a friend visiting a place you’ve been, it’s the perfect opportunity to send a recommendation for a great restaurant.” said Andrea Vaccari, Facebook Product Manager.

Facebook near by friends feature

Facebook will send GPS locations of customers continuously to its servers so that both users can see the location in real-time. However, if you are concerned about privacy then you may like to use the feature selectively. “We want to help you find your friends without sharing where you are,” Andrea Vaccari added. The feature opens a new door for Facebook to earn through sharing this information with various advertisers whether Facebook chooses to do so or not will be evident in future. It also opens new endeavors for hackers who can tap into all sorts of location-based personal data that may put users physically at risk. 

Tuesday, September 3, 2013

Get Independence From The Forgotten Internet Accounts With JustDelete.Me

Almost everything we do online remains stored somewhere and getting rid of the tracks is almost impossible. If you have old accounts you want to delete or social media sites you want erased, this new site named JustDelete.me can help.
The website, launched by designer Ed Poole and developer Robb Lewis, makes it a lot easier to ‘vanish’ from the Internet. Okay, maybe not permanently, but it is definitely the place to go if you’ve had it with your old accounts and want to start afresh.
JustDelete.me is basically a directory of links and information about how to delete specific accounts. When possible, it also lists direct links to web pages that allow you to delete your account. The website also ranks the services based on how easy or difficult it is to delete an account. The available categories are easy, medium, hard and impossible.
For instance, Google and Instagram are categorized as “easy,” since they make it very easy for the users to delete their accounts: they just have to log in and opt to delete. PayPal and IMDB are also in this category. Amazon and New York Times are listed as “hard” – Amazon users have to send a formal request to the company in order to delete their account.
And then there are websites such as Pinterest, Netflix, Craigslist, that are in the “impossible” category and seem to offer users no way to delete their accounts, even if they contact support.

JustDelete.me was launched on August 19 and had 16 services in its directory, but the number has since grown to over 130. A Google Chrome extension is also available.
many people said he decided to create this service after they found out how difficult it is to delete a Netflix or Skype account. And Poole explained that the popularity of their website since it was launched – over 500,000 views in the first week, is due to a growing public concern with Internet privacy, especially in light of the recent NSA spying scandal.

What do you think of this service? Would you consider using JutDelete.me to get rid of old accounts? Share your thoughts in the comments below.

Monday, July 8, 2013

Net Banking : July 2013 Cyber Safar Magazine નેટ બેન્કિંગ : જો જો ...!!! શોપિંગ ની મજા ન બને સજા ....!!!!

વ્હાલા વાચકમિત્રો ,  સમયના બ્રેક બાદ ફરી આપની સમક્ષ સાયબર સીક્યોરીટી ફિલ્ડ વિષે અવનવી રસપ્રદ માહિતીસભર આર્ટીકલ ફરીથી આપની સમક્ષ રજુ કરી રહ્યો છું . તે
પહેલા આટલા લાંબા અંતરાય નું વાજબી કારણ જણાવી દઉં .મિત્રો , 3 વર્ષ થી આ ફિલ્ડ માં કાર્યરત હોવાથી અનુભવ, જાણકારી તથા સતત અભ્યાસ દ્વારા એટલુ તારણ કાઢી શકું કે સાયબર ક્રાઈમ ના વધતા જતા વ્યાપ ને લીધે જેટલા બનાવો બને છે તેની પાછળનું કારણ મોટાભાગે જે-તે ભોગ બનેલા વ્યક્તિ ની બેદરકારી અથવા જાણકારી નો અભાવ જ હોય છે . સાયબર ક્રાઈમ ને લગતા વિવિધ બનાવો ધીમે ધીમે વધતા જતા હોવાથી આ ક્ષેત્ર માં નવી પેઢી ને જરૂરી અને યોગ્ય માર્ગદર્શનની સાથે સાથે પોતાનું ઉજ્જવળ કરિયર પણ બનાવી શકે તેવા હેતુ થી અમે એક સાયબર સીક્યોરીટી ટ્રેનીંગ સેન્ટર જુનાગઢ ખાતે શરુ કરેલ છે . જેમાં કોઈપણ વિદ્યાર્થી કે પ્રોફેશનલ
વ્યક્તિ સાયબર સિક્યોરીટી અને એથીકલ હેકિંગ ની સાથેસાથે અન્ય જરૂરી વિષયો પર જરૂરી માર્ગદર્શન મેળવી શકે છે તથા તેમાં પોતાનું કરિયર બનાવી શકે છે .

હવે મૂળ મુદ્દા પર આવીએ . તા :- 15 જૂન શનિવારે સવારે ન્યુઝપેપર માં મોટા અક્ષરો માં સમાચાર છપાયા કે મુંબઈની  એક્સીસ બેંકની શાખામાંથી પોલીસ ડીપાર્ટમેન્ટ સહીત કુલ 36 ખાતાઓમાંથી પંદર લાખ ની વધુ રકમ ની ઉચાપત કરવામાં આવી . પ્રાપ્ત વિગતો મુજબ મુંબઈ પોલીસ ના પગાર સહિતના બેંક ખાતા ને હેક કરીને ગ્રીસ માં કોઈ અજ્ઞાત શખ્સ દ્વારા લાખો રૂપિયા ઉપાડી લેવામાં આવ્યા . આ કેસ માં તપાસ કરી રહેલા ડીસીપી શ્રી વિનાયક દેશમુખ ના જણાવ્યા અનુસાર આ રકમ એટીએમ મશીન દ્વારા વિડ્રોલ કરવામાં આવી છે . જેમાં પોલીસ કર્મચારીઓ ના 12 એકાઉન્ટ માંથી 2,21,000 રૂપિયાનો પણ સમાવેશ થાય છે . સામાન્ય નાગરિકો ના હેક થયેલ બેંક એકાઉન્ટ ની તપાસ કરતા પોલીસ કર્મચારીઓ જ હેકિંગ નો ભોગ બનતા પોલીસ વિભાગ માં ખળભળાટ મચી ગયો છે . કેટલાક પોલીસ ને મોબાઈલ મેસેજ દ્વારા પોતાના રૂપિયા યુરો કરન્સી રૂપે ઉપડ્યા ની જાણ થઇ . પરંતુ ત્યારે બહુ મોડું થઇ ગયું હતું . એક્સીસ બેન્કે આ માટે મુંબઈ પોલીસનો સંપર્ક સાધતા રાજ્ય ના પોલીસ વડા શ્રી સંજીવ દયાલે સીનીયર અધિકારીઓ સાથે ની બેઠક બાદ આ નાણાં પરત મેળવવામાં આવશે તેવી ખાતરી આપી હતી.  

હવે એ નાણાં ક્યારે પાછા મળે, ક્યારે ગુનેગારો પકડાય, તેને સજા મળે ત્યાર ની વાત ત્યારે પણ હમણાં તો આપણે એ વિચારવાનું કે આવું કેમ થાય છે અને આપણી સાથે ના થાય તે માટે શું કરવું . એવું નથી કે અહી ભૂલ ખાતાધારકો કે પોલીસની છે પરંતુ વાત પાણી પહેલા પાળ બાંધવાની છે . જો બેન્કિંગ સેક્ટર માં બેદરકાર રહ્યા તો આવું આપની સાથે બનતા વાર નહિ લાગે . ઈ-કોમર્સ ક્ષેત્રમાં આવેલ ક્રાંતિ ના
પરિણામે નાનકડી બુક થી માંડી ને લાખો ની કાર પણ આપણે ઈન્ટરનેટ દ્વારા ખરીદી શકીએ . નેટ બેન્કિંગ દ્વારા આપણા માટે દુનિયાભરની વેપારી કંપનીઓ રેડ કાર્પેટ પાથરીને બેઠી છે . જાતજાતની લોભામણી ઓફરો થી નાના- નાના બાળકો થી માંડીને મોટેરાઓ સુધી ના તમામ વર્ગને આકર્ષવા દરેક વેબ્સાઈટ તૈયાર છે . ભૂખ લાગી છે...??? પીઝા મંગાવો ..., પિક્ચર જોવું છે ? ટીકીટ મંગાવો ... મેરેજ માં જવાનું
છે ??? કપડા મંગાવો .... ગર્લફ્રેન્ડ ને પ્રપોઝ કરવાનું છે ...??? ડાયમંડ રીંગ મંગાવો .... !!! ફેમીલી ટૂર પર જવું છે ???... રેલ્વે- ફ્લાઈટ ટીકીટ બુક કરાવો.... તમારે કોઈ વસ્તુ માટે દુકાન સુધી લાંબુ થવાની જરૂર જ નથી . અને પેમેન્ટની પણ કોઈ ચિંતા નથી ..ક્રેડીટ કાર્ડ - ડેબીટ કાર્ડ દ્વારા ગમે તે ખરીદી શકો
છો એ પણ ઘેરબેઠા . દરેક બેંક હવે નેટ-બેન્કિંગ અને મોબાઈલ બેન્કિંગ ની સુવિધા આપે જ છે .

*નેટ બેન્કિંગ  :- કેટલું પ્લસ કેટલું માઈનસ ?*

 નેટ બેન્કિંગ ની સુવિધા ગ્રાહકો માટે આશીર્વાદ સમાન ગણી શકાય . આ માટે દરેક બેંક દ્વારા ગ્રાહકો ની સુરક્ષા ને ધ્યાન માં લઈને SSL (સિક્યોર સોકેટ લેયર) ધરાવતા પેજ પર જ ટ્રાન્ઝેક્શન થાય તેવો આગ્રહ રાખવામાં આવે છે . બેંક પોતે પણ ખાસ હાઈ-ફાઈ સિક્યોર નેટવર્ક સિસ્ટમ વડે સજ્જ હોય છે જેમાં બ્રીચ (ભંગાણ) ની શક્યતા નહીવત હોય છે . તો પછી ? આટલા બેન્કિંગ ફ્રોડ ના બનાવો કેમ બને છે ?
કેમ કોઈ નું બેન્કિંગ એકાઉન્ટ હેક થઇ જાય ? કેમ કોઈ ના ખાતામાંથી પૈસા ઉપડી જાય ? મોટાભાગે ખાતેદાર કે ગ્રાહક ની નાનકડી ભૂલ ને કારણે જ બનાવો બનતા હોય છે. મોટાભાગના ગ્રાહકો નેટબેન્કિંગ માટે પર્સનલ કમ્પ્યુટર નો ઉપયોગ કરે છે . મોટાભાગના પર્સનલ કમ્પ્યુટર પોતે જ સુરક્ષિત હોતા નથી . ખાસ કરીને વિન્ડોઝ પર ચાલતા પીસી . આવા લૂપહોલ્સ (સુરક્ષા માં ખામી) નો લાભ લઈને હેકર્સ તમારા
ઈન્ટરનેટ બેંક એકાઉન્ટ ને એક્સેસ કરીને તમારી ઓળખ આપીને ફ્રોડ કરી શકે છે . કેટલીક વાર બેંક આ તફાવત ને ઓળખવામાં નિષ્ફળ નીવડે છે અને જ્યાં સુધી માં તમને ખબર પડે ત્યાં સુધીમાં તો તમારા રૂપિયાનો ઉપાડ કે ટ્રાન્સફર થઇ ચુક્યું હોય છે.

તો ચાલો હવે જાણીએ કે આવું આપણી સાથે ના થાય તે માટે કઈ કઈ સાવચેતીઓ રાખવી
જોઈએ . નેટ બેન્કિંગ માટે મુખ્યત્વે બે પ્રકારની સિક્યોરીટી  પડે છે .
1) ઓનલાઈન - સર્વર સિક્યોરીટી
2) ઓફલાઈન - ડેસ્કટોપ સિક્યોરીટી
જો તમે તમારા કાર્યક્ષેત્ર માં કે કોઈ જાહેર જગ્યાએ જેમ કે મોલ્સ , સાયબર કાફે
જેવી જગ્યા એ નેટ બેન્કિંગ કરતા હો તો તે જોખમી છે કારણ કે મોટાભાગના પબ્લિક પ્લેસમાં કમ્પ્યુટર સેફટી પર ધ્યાન આપવામાં આવતું નથી . હેકર્સ માટે આવા ખુલા પીસી મોકળુ મેદાન બની રહે છે . તેઓ આવા કમ્પ્યુટર માં જાતજાત ના હેકિંગ સોફ્ટવેર - જેવા કે કી- લોગર્સ, સ્પાયવેર , ટ્રોજન્સ વગેરે . જેના દ્વારા
તમારા યુઝર આઈડી અને પાસવર્ડ સહીત બધી માહિતી ચોરી ને તેનો દુરુપયોગ કરી શકે
છે .

*ઉપાય :*- દરેક બેંક વેબસાઈટ પોતાના ઈન્ટરનેટ બેન્કિંગ ના ગ્રાહકોની સુરક્ષા
ને ધ્યાન માં રાખીને વર્ચ્યુઅલ કીપેડનો ઓપ્શન રાખે છે જેથી કરીને આવા
કી-લોગર્સ થી બચી શકાય . સાથોસાથ કમ્પ્યુટરમાં એક વાર સ્પાયવેર સ્કેનર વડે
સ્કેન કરીને પછી ટ્રાન્ઝેક્શન કરવું વધુ હિતાવહ છે .


ઓનલાઈન શોપિંગ વખતે ક્યારેય ઉતાવળમાં અજાણી લિંક પર કે અચાનક ડિસ્પ્લે થતી
વિન્ડો પર ક્લિક ના કરવું . દા . ત ., મોટાભાગના બ્રાઉઝરમાં પાસવર્ડ સેવ
કરવાનો ઓપ્શન આપેલો હોય છે કે જેવો તમે પાસવર્ડ નાખો કે તરત જ બ્રાઉઝર તમારે એ
પાસવર્ડ સેવ કરવો છે કે નહિ તે પૂછે છે . કેટલાક લોકો વાચ્યા વગર જ OK કે YES
બટન ક્લિક કરી દે છે અને તમારો પાસવર્ડ બ્રાઉઝર માં સેવ થઇ જાય છે . જે
પાસવર્ડ ને અમુક ટુલ્સ વડે આસાનીથી કોઈપણ વ્યક્તિ જોઈ શકે છે .

જો આપ ઈન્ટરનેટ બેન્કિંગ ઘરેથી જ કરતા હોય તો પણ તમારે વધુ સાવધાની રાખવાની
જરૂર રહે છે . કમ્પ્યુટર માં તો ચાલો ઠીક છે  કે કલાક બેઠા અને તેટલા સમય
પુરતી સાવધાની રાખીએ એટલે ચાલે પણ પર્સનલ કમ્પ્યુટર પર તો ઈન્ટરનેટના વપરાશનું
કોઈ માપ ન રહેતું હોવાના લીધે કોઈ સમયમર્યાદા રહેતી નથી . એક કાઠીયાવાડી કહેવત
મુજબ  "બિલાડી ઘર ભાળી જાય " તેમ હેકર્સ તમારી નાનકડી લાપરવાહી ની જ રાહ જોતા
હોય છે કે જેથી તમારા પીસી માં યેનકેન પ્રકારે પ્રવેશ મેળવી શકે . જો એકવાર
તેના ટ્રોજન કે સ્પાયવેર કે કી-લોગર્સ કે અન્ય કોઈ સોફ્ટવેર દ્વારા તે તમારા
કમ્પ્યુટર માં પ્રવેશ મેળવી લે તો કાયમી ધોરણે તમારા કમ્પ્યુટર નો ઉપયાગ કરવા
સક્ષમ છે .

ઉપાય :- સૌપ્રથમ તમારા ડેસ્કટોપ વિષે પુરેપુરી જાણકારી મેળવી લો કે તે તે
બધી રીતે સેફ છે કે નહિ . જો કોઈ ખામી હોય તો તેનું યોગ્ય નિવારણ કરો . જેમ કે
સિસ્ટમ સ્કેન કરવી, એન્ટીવાઈરસ અપડેટ કરવો , ફાયરવોલ ઓન કરવી  વગેરે .

"....ઈન્ટરનેટ ફ્રોડ કેસ માંથી 14 % જેટલા ફ્રોડ કેસ ક્રેડીટ કાર્ડના હોય છે . આવા
કેસ માં મોટાભાગે ક્રેડીટ કાર્ડ કમ્પની પાસે તેના દરેક ટ્રાન્ઝેક્શન ની રજેરજ
ની માહિતી હોવાથી આવ કેસમાં વહેલા-મોડા ક્રિમિનલ્સ પકડાઈ જતા હોય છે પણ ત્યાં
સુધી માં જે તો ગ્રાહકની રકમ વપરાઈ જ ગઈ હોય છે ...."

*ઉપાય :-*  ક્રેડીટ કાર્ડ વાપરો કે ના વાપરો , દર મહીને તેના સ્ટેટમેન્ટ થી
વાકેફ રહો . કોઈપણ શંકાસ્પદ ટ્રાન્ઝેક્શન જણાય તો તરત જ બેંક નો સંપર્ક કરો .
ક્રેડીટ કાર્ડ નમ્બર નાખતી વખતે વેબપેજ SSL લેયર પર છે કે નહિ તે ચેક કરી
લેવું .

મોબાઈલ બેન્કિંગ :- જમાના સાથે હાઈટેક થતી બેંક માં ગ્રાહકોની સુવિધા માટે
દરેક બેંક હવે મોબાઈલ બેન્કિંગ ની સુવિધા આપે છે . આપના નાના-મોટા બીલ ભરવા
માટે ,મોબાઈલ રીચાર્જ કરવા, પૈસા ટ્રાન્સફર કરવા સહીત ની ઘણી સુવિધા મોબાઈલ પર
પૂરી પાડે છે . મોબાઈલ બેન્કિંગ સેફટી અંગે તો એટલું જ ધ્યાન રાખવાનું કે
તમારો મોબાઈલ જ્યાં સુધી તમારી પાસે છે ત્યાં સુધી જ સુરક્ષિત છે . જો તમારો
મોબાઈલ ચોરાઈ ગયો અને ભૂલથી તમારું બેન્કિંગ એકાઉન્ટ ઓપન રહી ગયું તો મુસીબત
માં મુકાઈ શકો છો .

*ઉપાય :-*  મોબાઈલ માં ભલે કંટાળો આવે છતાં લોગીન - લોગ-આઉટ ની ટેવ રાખો .
કોઈપણ બેન્કિંગ ટ્રાન્ઝેક્શન નો મેસેજ મોબાઈલ દ્વારા મળી જાય તે માટે SMS
સર્વિસ ઓન રાખો . મોબાઈલ માં એન્ટી થેફ્ટ સોફ્ટવેર ઓન રાખો . અને બને તો
મોબાઈલ બેન્કિંગનો ઉપયોગ નાછૂટકે જ કરવો .

આ ઉપરાંત ના કેટલીક ઉપયોગી સિક્યોરીટી ટીપ્સ સેફ ઈન્ટરનેટ બેન્કિંગ માટે :-
- નકલી બેંક વેબસાઈટ થી સાવચેત રહો . હેકર્સ તમને તેની નકલી વેબસાઈટ પર ગમે તે રીતે આકર્ષવાનો પ્રયત્ન કરશે . પણ નેટબેન્કિંગ વખતે હમેશા વેબસાઈટનું URL ચેક કરી લેવું . કારણ કે ચાલક હેકર્સ બેંક ની વેબસાઈટના ભળતા નામ પર જ નકલી વેબસાઈટ બનાવે છે . દા .ત . , www.axisbankonline.com એ સાચી બેન્કિંગ વેબસાઈટ છે જેના પરથી હેકર્સ નકલી વેબસાઈટ બનાવે છે www.axisonlinebank.comબનાવે છે . જેમાં ગ્રાહક ભોળવાઈ જાય છે .
 
- બેંક ની ઈન્ટરનેટ પોલીસી ને એક વાર નિરાતે વાચી લેવી . કેટલીક બેંક માં અમુક રકમ થી વધારે ટ્રાન્સફર કરવા માટે એક અલગ સ્ટ્રોંગ પાસવર્ડ હોય છે .

- દર મહીને પાસવર્ડ બદલતા રહો અને તેને ક્યાય લખવાના બદલે માત્ર યાદ રાખો .
   
- ધારી શકાય તેવા પાસવર્ડ ના રાખવા જેમ કે વ્યક્તિનું નામ , જન્મતારીખ , મોબાઈલ નંબર વગેરે
   
- આપના બ્રાઉઝર ને અને ઓપરેટીંગ સિસ્ટમ ને અપડેટ રાખો . સિક્યોરીટી સોફ્ટવેરને પણ રેઅ ગ્યુલર અપડેટ રાખો . સિક્યોરીટી સોફ્ટવેર હમેશા વિશ્વાસુ વેબસાઈટ પરથી જ ડાઉનલોડ કરવાનો આગ્રહ રાખવો .
   
- ઓનલાઈન શોપિંગ કે પેમેન્ટ કર્યા પછી બેન્કિંગ પોર્ટલ ને લોગ - આઉટ કરવાનું ભૂલશો નહિ . પબ્લિક કમ્પ્યુટર માંથી સીધું બ્રાઉઝર બંધ કરવાને બદલે તેની હિસ્ટ્રી અને સેશન ક્લીયર કરી નાખવા .
   
- એન્ટીવાઈરસ ની ફાયરવોલ ઉપરાંત એક ફાયરવોલ ઇન્સ્ટોલ કરી રાખો અને તેને રોજ
   ઓટોમેટીક અપડેટ કરાવો .

- ઘણી બેંકોમાં "Last Login Panel" ની લિંક આપે છે . તેનો સદુપયોગ કરવો . જો કોઈ શંકાસ્પદ ટ્રાન્ઝેક્શન જણાય તો બેંકનો સંપર્ક કરવો।
   
- ઈન્ટરનેટ બેન્કિંગ કરતી વખતે કમ્પ્યુટર ખુલ્લું છોડીને જવું નહિ .
   
- વારેવારે આવતા લોભામણી જાહેરાતો ના ઈ-મેઈલ્સ થી છેતરાવું નહિ .
  
 - બેંક ના નામે આવતા ઈ-મેઈલ્સ માં જો ઈ-મેઈલ-આઈડી , પાસવર્ડ, ક્રેડીટ કાર્ડ નમ્બર કે અન્ય પર્સનલ માહિતી આપવી નહિ . આવા વ્યવહારો બને ત્યાં સુધી બેંક માં રૂબરૂ જ કરવા .
   
- જો એક કરતા વધારે બેંક એકાઉન્ટ વાપરતા હોય તો બધા માટે સરખો પાસવર્ડ
   વાપરવો નહિ .
  
- શક્ય હોય ત્યાં સુધી ક્યારેય સાયબર કાફે માંથી ઓનલાઈન શોપિંગ ન કરવી કેમ
   કે બેંક ફ્રોડ નો સુધી વધુ ખતરો ત્યાં જ રહે છે .
   
- વેબ્સાઈટમાં નીચે જમણી તરફ પેડલોક નો સિમ્બોલ ચેક કરી ને જ આગળ પ્રોસેસ
   કરવી.
  
તો આ રીતે ઓનલાઈન બેન્કિંગ સુવિધાનો સલામત રહીને ઉપયોગ કરવાથી આ સેવા આપના
માટે આશીર્વાદરૂપ બની રહે છે અને જમાનાથી એક કદમ આગળ રહીને મોટી મોટી લાઈનો થી
બધીને સમય અને શક્તિ નો બચાવ કરી શકીએ છીએ .

આપના અભિપ્રાયો તથા પ્રશ્નો આવકાર્ય છે :- ઈ-મેઈલ  :- milap_magic@yahoo.co.in
લેખક :- મિલાપ ઓઝા
સાયબર સિક્યોરીટી એક્સપર્ટ
એપીન ટેકનોલોજી લેબ , જુનાગઢ
90330 18333

Wednesday, July 3, 2013

National Cyber Security Policy 2013

The Government of India on 1 July 2013 launched the National Cyber Security Policy 2013 with an aim to protect information and build capabilities to prevent cyber attacks. The National Cyber Security Policy 2013 is to safeguard both physical and business assets of the country.
Earlier, the Government of India on 8 May 2013 approved the National Cyber Security Policy with an aim to create a secured computing environment across the country.
The salient features of the National Cyber Security Policy 2013
The Policy outlines the roadmap for creation of a framework for comprehensive, collaborative and collective responsibility to deal with cyber security issues of the country. The policy has ambitious plans for rapid social transformation and inclusive growth and India’s prominent role in the IT global market.
The policy lays out 14 objectives which include creation of a 5,00,000-strong professional, skilled workforce over the next five years through capacity building, skill development and training.
The policy plans to create national and sectoral level 24×7 mechanisms for obtaining strategic information regarding threats to ICT infrastructure, creating scenarios for response, resolution and crisis management through effective, predictive, preventive, proactive response and recovery actions.
The policy will also establish a mechanism for sharing information as well as identifying and responding to cyber security incidents and for cooperation in restoration efforts.
The policy identifies eight different strategies for creating a secure cyber eco-system including the need for creating an assurance framework apart from encouraging open standards to facilitate inter-operability and data exchange amongst different products or services.
There is in place a plan to operate and strengthen the national Computer Emergency Response Team (CERT-In) to operate 24×7 and to act as a nodal agency for all efforts for cyber security, emergency response and crisis management, as an umbrella agency over CERTs.
It is expected that he policy will cater to the cyber security requirements of government and non-government entities at the national and international levels. The policy will help in safeguarding the critical infrastructure like Air Defence system, nuclear plants, banking system, power infrastructure, telecommunication system and many more to secure country’s economic stability.
National Nodal Agency
The National Cyber Security Policy, in order to create a secure cyber ecosystem, has planned to set-up a National Nodal Agency. The nodal agency will be coordinating all matters related to cyber security in the country.
The nodal agency has a wide mandate as it will cover and coordinate security for all strategic, military, government and business assets. This is distinctive, since, so far, national security regimes have been divided among the Ministry of Defence (for securing India’s borders) and the Ministry of Home Affairs (for national and internal security across States).
Public-private partnership to protect national assets
Another defining aspect of the policy is the level at which it envisages public-private partnership to protect national assets.
There is a clear recognition in the policy that, apart from India’s IT, technology and telecommunications services, large parts of financial & banking services, airline & transportation services, energy and healthcare assets are not only owned by the private sector but, in fact, remain vulnerable to cyber-attacks, both from state and non-state actors.
Protection centre
A crucial aspect of the policy is building resilience around the Critical Information Infrastructure (CII) by operationalising a 24×7 Nation Critical Information Infrastructure Protection Centre (NCIIPC). The Critical Information Infrastructure will comprise all interconnected and interdependent networks, across government and private sector.
The NCIIPC will mandate a security audit of CII apart from the certification of all security roles of chief security officers and others involved in operationalising the CII.
Operationalisation
The policy will be operationalised by way of guidelines and Plans of Action, notified at national, sectoral, and other levels. While there is a recognition of the importance of bilateral and multilateral relationships, the policy does not clearly identify India’s position vis-à-vis the Budapest Convention even though government delegations have attended meetings in London and Budapest on related issues in 2012.
Why does India need a cyber security policy?
Cyber security is critical for economic security and any failure to ensure cyber security will lead to economic destabilization.
India already has 800 million active mobile subscribers and 160 million other Internet users of which nearly half are on social media. India targets 600 million broadband connections and 100% teledensity by 2020. Internet traffic in India will grow nine-fold by 2015 topping out at 13.2 exabytes in 2015, up from 1.6 exabytes in 2010.
The ICT sector has grown at an annual compounded rate of 33% over the last decade and the contribution of IT and ITES industry to GDP increased from 5.2% in 2006-7 to 6.4% in 2010-11, according to an IDSA task force report of 2012.
Given the fact that a nation’s cyber ecosystem is constantly under attack from state and non-state actors both. It becomes extremely critical for India to come up a coherent cyber security policy.
One of the key objectives for the government is also to secure e-governance services where it is already implementing several nationwide plans including the “e-Bharat” project, a World Bank-funded project of Rs. 700 crore.

Sunday, June 2, 2013

My Latest Article in Kathiyavad POst : Mission Education - 2013 *** ભારત માં ઇન્ફોર્મેશન સિક્યોરીટી ક્ષેત્રે કારકિર્દી ની ઉજ્જવળ તક **


ભારતમાં ઇન્ફોર્મેશન સિક્યોરીટી ક્ષેત્રે કારકિર્દીમાં વિપુલ સંભાવનાઓ રહેલી છે . આધુનિક યુગમાં કમ્પ્યુટર સિક્યોરીટી એ દરેક નાના મોટા બીઝનેસ તથા પર્સનલ લાઈફ માં અનિવાર્ય છે . કોઈપણ બીઝનેસ માં કે અંગત જીવન માં પ્રાઈવેટ ઇન્ફોર્મેશન ની સિક્યોરીટી અંગે ખાસ મહત્વ આપવામાં આવે છે .

તાજેતર ના રીસર્ચ રીપોર્ટ પ્રમાણે 2013 માં ગ્લોબલ ઇકોનોમિક સ્લોડાઉન અને ઇન્ફોર્મેશન સિક્યોરીટી એ દરેક નાની મોટી કંપનીઓ માટે ચિંતાનો વિષય બની રહ્યો છે . ઉપરાંત 2008-09 થી આઈટી સિક્યોરીટી નું માર્કેટ 60 બિલિયન યુએસ ડોલર નું થઇ ગયું છે જેમાં 2013 સુધીમાં દર વર્ષે સરેરાશ 12% નો વધારો થઇ રહ્યો છે .

2007 - ઇન્ફોર્મેશન સિક્યોરીટીની સર્વિસ અને પ્રોડક્ટ્સ નું માર્કેટ અંદાજીત $ 54.5 બિલિયન નું હતું . પરંતુ ત્યારે આ માર્કેટ અમુક વિકસિત દેશો જેવા કે યુએસ , કેનેડા, ફ્રાંસ ,ઇટલી, જર્મની , જાપાન અને યુકે પુરતું મર્યાદિત હતું . 

2009 - ગ્લોબલ સિક્યોરીટી માર્કેટ માં વાર્ષિક 15.5% નો વધારો .

2012 - પૃથ્વી ના પ્રલય ની અફવાઓથી પણ સિક્યોરીટી માર્કેટ 17.5 % ના વધારા સાથે આ બીઝનેસ માં 38.3 બિલીયન યુએસ ડોલર્સ નો વધારો થયો .

ઇન્ફોર્મેશન સિક્યોરીટી અને એથીકલ હેકિંગ

ઇન્ફોર્મેશન સિક્યોરીટી એ કોઈપણ હાર્ડવેર , સોફ્ટવેર કે નેટવર્ક ને કોઈપણ કુદરતી આફતો સમયે અથવા તો વાયરસ કે હેકિંગ એટેક વગેરે થી સુરક્ષિત રાખવા માટે અત્યંત આવશ્યક છે . ખાસ કરીને ઈલેક્ટ્રોનિક ડેટા કે જે કોઈપણ કંપની માટે સૌથી સંવેદનશીલ પરિબળ છે . બીજા શબ્દો માં કહીએ તો ઇન્ફોર્મેશન ને તથા ઇન્ફોર્મેશન સિસ્ટમ ને બહારના અનધિકૃત વ્યક્તિઓ , હરીફો તથા કમ્પ્યુટર ક્રિમિનલ્સ થી બચાવવી એ દરેક કમ્પની ની પ્રાથમિક જરૂરિયાત હોય છે . ઇન્ફોર્મેશન સિક્યોરીટી પ્રોફેશનલ્સ ને અન્ય પ્રોફેશનલ્સ કે ડેવલપર્સ ની સરખમણી એ  ક્યારેય રીસેશન નડતું નથી . એક સર્વે પ્રમાણે સાયબર ક્રાઈમ ની વધતી જતી સમસ્યા ના કારણે સાયબર સિક્યોરીટી ક્ષેત્રે જે લોકો પોતાના ટેલેન્ટ ને કોમ્પુટર ઇન્વેસ્ટીગેશન તરીકે અજમાવવા માંગે છે તેમના માટે અહી સુવર્ણ તક રહેલી છે . કારણ કે સાયબર ક્રાઈમ્સ નો વધતો જતો ઉપદ્રવ થોડા ઘણા અંશે બધા ને અસર તો કરે જ છે .

શા માટે ઇન્ફોર્મેશન સિક્યોરીટી જરૂરી છે ?

છેલ્લા પાંચ વર્ષો માં હેકિંગ ના ગુનાઓ , ડેટા ની ચોરી , વાયરસ વગેરે સાયબર ક્રાઈમ્સ નો વ્યાપ ચિંતા નો વિષય બની ગયો  છે . આ જ કરને ઇન્ફોર્મેશન સિક્યોરીટી આજે બોર્ડરૂમ લેવલ નો ચર્ચા નો મુદ્દો બની ચુક્યો છે . આ માટે ની ટ્રેનીંગ તથા પ્રોડક્ટ્સ ની હવે દરેક કંપનીઓ ને જરૂર પડે જ છે . કમ્પનીના કર્મચારીઓ પાસે બેઝીક સિક્યોરીટી નું જ્ઞાન ન હોવાથી ભારત માં ઘણી કંપનીઓમાં ઇન્ફોર્મેશન સિક્યોરીટી ના નિયમોનું પાલન ફરજીયાતપણે કરાવવામાં આવે છે . વિશ્વસ્તરે ઇન્ફોર્મેશન સિક્યોરીટી ઇન્ડસ્ત્રી 21% ના વાર્ષિક ગ્રોથ સાથે આગળ વધી રહી છે .

સાયબર સિક્યોરીટી ક્ષેત્રે કેરિયર

2012 થી જ એશિયન-પેસિફિક  દેશો માં ઇન્ફર્મેશન સિક્યોરીટી સ્લોયુશન્સ  નું માર્કેટ જોરદાર રહેવા લાગ્યું છે . દુનિયાના કોઈ પણ મોટા સેક્ટર ઇન્ફોર્મેશન સિક્યોરીટી સેક્ટર સાથે કોઈ ને કોઈ રીતે સંકળાયેલા  છે .
જેમ કે
  •     બેન્કિંગ સેક્ટર
  •     એવિએશન  ઇન્ડસ્ટ્રી
  •     કોર્પોરેટ સેક્ટર
  •     એજ્યુકેશનલ ઇન્સ્ટીટ્યુશન
  •     આઈટી , સોફ્ટવેર
  •     BPO , KPO
  •     ટેલીકોમ સેક્ટર
  •     ઈ-કોમર્સ  બીઝનેસ
  •     ગવર્મેન્ટ સેક્ટર
    જેવા કે
        સાયબર ક્રાઈમ ઇન્વેસ્ટીગેશન સેલ
        ગ્લોબલ સિક્યોરીટી એજન્સી
        ઇન્ફોર્મેશન સિસ્ટમ સિક્યોરીટી એસોસીએશન
        નેશનલ ઇન્ફોર્મેશન સિક્યોરીટી ટેસ્ટીંગ એન્ડ સર્ટીફીકેશન સેન્ટર

કઈ કઈ જોબ્સ મેળવી શકો ...?
સાયબર સિક્યોરીટી ક્ષેત્રે નોકરીઓ ની શ્રેષ્ઠ તકો ઉપલબ્ધ છે . જેમાંથી કેટલીક પોસ્ટ નીચે મુજબ છે .
  •     સાયબર સિક્યોરીટી પ્રોફેશનલ
  •     ઇન્ફોર્મેશન સિક્યોરીટી પ્રોફેશનલ
  •     IS એક્ઝીક્યુટીવ
  •     ઇન્ફોર્મેશન સિસ્ટમ ઓડીટર
  •     સિક્યોરીટી એડવાઈઝર
  •     સોફ્ટવેર ડેવલપર
  •     આઈટી સ્પેશ્યાલીસ્ટ
  •     આઈટી સીસ્ટમ એક્ઝીક્યુટીવ
  •     આઈટી કન્સલટંટ
  •     જુનીયર પ્રોગ્રામર
  •     આસીસ્ટંટ સોફ્ટવેર ડેવલપર
  •     જુનીયર સોફ્ટવેર ટેસ્ટ એન્જીનીયર
  •     R & D એક્ઝીક્યુટીવ
  •     સિક્યુરીટી કન્સલ્ટન્ટ
  •     સીસ્ટમ એન્જીનીયર
  •     નેટવર્ક એન્જીનીયર
  •     નેટવર્ક એડ્મીનીસ્ટ્રેટર
  •     ટેકનોલોજી એવેન્જેલીસ્ટ  વગેરે વગેરે .....

તો આ પ્રકાર ની કરિયર પ્રોફાઈલ દ્વારા વિદ્યાર્થીઓ પોતાના ગ્રેજ્યુએશન દરમિયાન જ આકર્ષક પેકેજીસ ધરાવતી જોબ્સ મેળવી શકે છે . એક રીસર્ચ પ્રમાણે હાલ માં ભારત માં 4 લાખ 50 હજાર સિક્યોરીટી પ્રોફેશનલ્સ ની જરૂર છે જેની સામે અત્યારે માત્ર 45 થી 50 હજાર કાબેલ પ્રોફેશનલ્સ છે . તો આપ વિચારી શકો છો કે આ ક્ષેત્ર માં કરિયર બાદ ભરપુર તકો રહેલી છે . સર્ટીફાઇડ એથીકલ હેકર્સ ની દરેક કમ્પની માં માંગ છે .

દર વર્ષે હજારો વિદ્યાર્થીઓ અલગ અલગ કોલેજ તથા યુનીવર્સીટી માંથી ગ્રેજ્યુએશન કરીને બહાર નીકળે છે . પરંતુ માત્ર કોલેજમાં  ટોપ સ્કોર કરેલા વિદ્યાર્થીઓ સિવાય મોટા ભાગના વિદ્યાર્થીઓ ની સારી કમ્પની માં જોબ ની આશા પર પાણી ફરી વળે છે . કેટલાક નાની મોટી જોબ કરીને સંતોષ રાખે છે તો કેટલાક તો વળી સાવ બેકાર રહે છે . આ માટે નું કારણ એ છે કે કંપનીઓ માં માત્ર ટેલેન્ટેડ અને જેમની પ્રેક્ટીકલી કુશળ હોય એવા જ લોકો ને જોબ મળે છે . જેથી તેઓ જોબ ના પહેલા દિવસ થી જ પોતાનો કાર્યભાર કુશળતા થી સંભાળીને કમ્પની ને મદદરૂપ થાય .

આ માટે જ સાયબર સિક્યોરીટીના ફિલ્ડ માં અમુક કંપનીઓ પ્રોફેશનલ ટ્રેનીંગ પૂરી પાડે છે જે ઇન્ડસ્ટ્રીની જરૂરિયાતો પ્રમાણે તેમને સર્વિસ પૂરી પાડી શકે . ભારત માં આ માટે અમુક પ્રખ્યાત આઈટી સિક્યોરીટી કંપનીઓ વિદ્યાર્થીઓ ને આ માટે ની ઉત્તમ ટ્રેનીંગ આપીને સારા માં સારી જોબ અપાવે છે . હવે આઈટી સિક્યોરીટી માં ડીપ્લોમાં તથા ડીગ્રી પણ મેળવી શકાય છે જે ખુબ જ ઉજ્જવળ કારકિર્દી માટે આવશ્યક છે . આ માટે અમુક યુનીવર્સીટી માં આ માટે ના અલગ અભ્યાસક્રમો ઉપલબ્ધ છે . સામાન્ય રીતે મોટા ભાગના અભ્યાસક્રમો ધો। 12 પછી કરી શકાય છે . આ માટે BCA , ડીપ્લોમાં ઇન ઇન્ફોર્મેશન સિક્યોરીટી , ઉપરાંત સર્ટીફીકેટ કોર્સ બેસ્ટ રહેશે .

સાયબર સિક્યોરીટી નો કન્સેપ્ટ ભારત માં નવો છે અને સફળતા ના શિખર સુધી લઇ જનારો છે . સાયબર ક્રાઈમ્સ નો ઉપદ્રવ વધી રહ્યો છે અને હજી પણ વધતો જતો હોવાને  લીધે આ સેક્ટરમાં અત્યારે ચાંદી છે  . સાયબર ક્રિમિનલ્સ ને પકડવા કે ખુલ્લા પાડવા માટે અને તેની સામે ના રક્ષણ માટે એક સિક્યોરીટી સ્પેશ્યાલીસ્ટ તરીકે એકદમ કૂલ , પ્રતિષ્ઠિત અને પૈસા કમાવાની સોનેરી તકો અહી રહેલી છે .

અહી કેટલીક યુનીવર્સીટી તથા પ્રતિષ્ઠિત કંપનીઓ દર્શાવેલ છે જ્યાંથી આપ આ કોર્સ માટેની માહિતી મેળવી શકો છો . ઉપરાંત ધ્યાન માં રહે કે ડિસ્ટન્સ લર્નિંગ કરતા રેગ્યુલર માં જ ટ્રેનીંગ વધુ હિતાવહ છે . 
  •     Appin Technology Lab - New Delhi - Certification, Diploma, Degree & Master in Information Security
  •     Asian School of Cyber Law - Pune - Diploma & Certification in Cyber Law
  •     Madras University - Chennai - Msc. in Information Security
  •     IMT - Gaziabad - Msc. in Cyber Security
  •     Innobuzz - Certification
  •     AFCEH - Certification

લેખક :- મિલાપ ઓઝા -
ઇન્ફોર્મેશન સિક્યોરીટી  એક્સપર્ટ
એપીન ટેકનોલોજી લેબ - જુનાગઢ
આ લેખ અંગે ના આપના પ્રતિભાવો કે પ્રશ્નો આપ ઈ-મેઈલ કે ફોન દ્વારા જણાવી શકો છો .
કોન્ટેક્ટ નં : 90330 18333
ઈ-મેઈલ - milap_magic@yahoo.co.in
Web : milapoza.blogspot.com

Monday, December 24, 2012

Non-Windows attacks will increase in 2013


Android devices are now the highest selling mobile devices in the Asia Pacific market and hackers will take advantage of that by developing mobile malware.As your work and play converges even more on a digital device - a tablet, smartphone or the laptop, beware of the increasing threats. Android devices are now the highest selling mobile devices in the Asia Pacific market and hackers will take advantage of that by developing mobile malware. Consumers aren't the only ones at risk of mobile threats.


Enterprises, particularly those embracing Bring Your Own Device (BYOD), are also at risk. Overall, non-Windows attacks will increase in 2013. Software security expert McAfee, an Intel company, in a release, looks at the threats to computers in 2013: 

Top 10 Enterprise Security Predictions 

1. Targeted Attacks: 2012 saw an increased growth in targeted attacks that proved successful in disrupting service and fraudulently obtaining significant amounts of intellectual property. We expect cyber criminals will continue to use this method and as a result, in 2013, we are likely to see significantly more targeted attacks and targeted malware. This type of attack is more difficult to protect against. Uniform attacks are still out there but as soon as they are identified and a security fix is released they are no longer effective. 

One disturbing development in this trend across 2012 was that we started to see more targeted attacks that destroyed evidence of the attack afterwards and we are likely to see this continue. We have seen attacks where 30,000 hard drives were left non-operational after an attack. Dealing with the clean-up distracts the IT administrators who don't immediately realize they have been hacked. It also adds to the difficulty in ensuring effective incident response as hackers literally attack any hardware on the way out. Protecting against this will be a major challenge - particularly for enterprise and government. 

2. Signed malware: Signed malware was prevalent in 2012 and this is likely to continue. Signed malware is present when a hacker obtains a digital certificate from an organization and appends it to malware, allowing the malware to pass through an organization's operating system. Stuxnet is a high profile example of this threat. There will be a large increase in this type of threat and it will be harder to stop because it appears more legitimate. 

3. Big business at risk: Enterprises can be at a higher risk of an attack as there is often a greater attack surface and more 'visibility gaps' in their security posture. With targeted attacks on the rise, the motives to target a large enterprise are often greater than a smaller organization. 

4. Non-Windows attacks: We suspect non-Windows attacks will continue to increase in 2013. Android devices are now the highest selling mobile devices in the Asia Pacific market and hackers will take advantage of that by developing mobile malware. Consumers aren't the only ones at risk of mobile threats.

Enterprises, particularly those embracing Bring Your Own Device (BYOD), are also at risk. Interestingly, the mobile malware growth rate is similar to what we saw for Windows malware some time ago, which shows it is a genuine threat. McAfee's Q3 Threat Report for 2012 showed mobile malware almost doubled when compared to the previous quarter's numbers. 

5. Ransomware: This will also be prevalent in 2013. Ransomware is operated by encrypting files on a victim's computer which can only be unlocked by paying the criminals a 'fine'. It has been a big issue in other countries around the world in the past. 
       

6. Impact of changing regulations: The Indian banking regulator (RBI) has generally been proactive in advising banks on issues relating to security and has acted as an important institution to drive the importance of this matter at the level of Board of Directors. According to the Reserve Bank of India report released in January 2011, the regulator acknowledges that given the increasing reliance of customers on electronic delivery channels to conduct transactions, any security related issues have the potential to undermine public confidence in the use of e-banking channels and lead to reputation risks to the banks.

The regulator has institutionalized a whistle-blowing system by means of a quarterly assessment of all banks towards their progress on these guidelines in the AFI (Annual Financial Inspection) cycle 2011-2012. To conform to these guidelines, financial services organizations in India will need to demonstrate compliance with RBI regulatory mandates, which include data protection, event collection and analysis, endpoint controls, and related security measures. 

7. Need for incident response: In 2013, organizations will have to review their processes for dealing with a targeted attack. If the organization falls foul from a targeted attack or Advanced Persistent Threat (APT) they will need to adopt a process of incident response and many organizations don't necessarily have the technologies in place to ensure timely investigation and remediation is possible. As such, solutions providing incident response capabilities will become a security infrastructure priority for many organizations over the next year. 

8. Security Process Automation: In many organizations cyber security function is one of the only IT functions that have not yet leveraged the speed, visibility and capabilities provided through automation. With an increasing number, variety and complexity of the threats faced by organizations, many security technologies still require hands-on management. We expect that IT managers will have to embrace security automation in order to keep up. 

9. Connected Devices: We also anticipate the growth in number and variety of new connected devices will provide additional gateways for hackers to access personal or business networks - these 'connected devices' include connected homes and connected cars. While the home or car may not be hacked, they are used as a vehicle to access other networks. 

10. Bring Your Own Application (BYOA): With BYOD comes Bring Your Own Applications where many employees are now downloading Apps within the organization. As a result IT administrators are losing control of what tools and applications are used inside the enterprise and business users (often lacking in an understanding of the potential security risks these applications can pose) are becoming their own system administrators.

There are many examples of Apps that transmit information with no security, Apps that leak sensitive information, through to Apps that are malicious and place the user and the information at risk. 


source:economictimes.com

Wednesday, September 12, 2012

2012 Norton Cybercrime report, a worrying scenario


Symantec and its report on cyber crime ” The yearly Norton Cybercrime report“, a document that analyzes the evolution of  cyber criminal activities and their impact on the society. The report covers different technologies including and social networking and mobile reporting the impact on final customers in economic terms.
The report involved 13018 participants across 24 countries aged 18-64 and a pool of expert collaborators.
The impact of cyber crime is worrying with 556 million of victims per year, 2 on 3 adults have been victims of on line illegals in their lifetime, the total economic loss is 110 Billion with an average cost per victim of $197.
 
The Asian region is the most affected by cybercrime, the global pricetag of consumer cybercrime for China amounts to 46 Billion , followed by US with 21 Billion and European Area with 16 Billion.
The highest numbers of cybercrime victims were found in Russia (92 percent), China (84 percent) and South Africa (80 percent).
The technologies that have suffered the major increase in cybercrime are social networking and mobile.
It has been registered an increase in cybercrime which takes advantage of social networks and mobile technology. Mobile users are very vulnerable to attacks, 2/2 adults use a mobile device to access the internet and the mobile vulnerabilities doubled in 2011 respect previous year.
44% of users aren't aware of the existence of solutions for mobile envitonments, and 35 of adults have lost their mobile device or had it stolen.
  
Of particular concern is an improper use of social networks, wrong management of sessions, absence of validation of visited links and a total ignorance of any security setting expose users to fraudulent activities.
15 percent of users have had their account infiltrated, and 1 in 10 have been victims of fake links or scams.
Other behavior extremely worrying is the way in which people use public networks and operate on it, for example accessing to private services such as email.
The email account are one of the most appetible targets for cybercriminals because they represent a simple way to access to sensible information.
When using public connections, 67 percent access email, 63 percent use social networking and 24 percent access their bank account, according to the report.”
I found really interesting the reading of the report of security firms that could give us a vision on the evolution of cyber threats and of course some practices to share for those users too “distracted” or un aware of the incoming risks.