久久亚洲国产成人影院-久久亚洲国产的中文-久久亚洲国产高清-久久亚洲国产精品-亚洲图片偷拍自拍-亚洲图色视频

Make me your Homepage
left corner left corner
China Daily Website

US govt warns merchants on Target hacking tricks

Updated: 2014-01-17 09:34
( Agencies)

BOSTON ?- The US government on Thursday provided merchants with information gleaned from its confidential investigation into the massive data breach at Target Corp, in a move aimed at identifying and thwarting similar attacks that may be ongoing.

The report titled "Indicators for Network Defenders" brings to light some of the first information gleaned from the government's highly secretive probes into the Target breach and other retail hacks, including details useful for detecting malicious programs that elude anti-virus software.

"It's a shame this report wasn't released a month ago," said Dmitri Alperovitch, chief technology officer of the cybersecurity firm CrowdStrike. "It has been frustrating for some retailers because it has been incredibly difficult for most firms to get information. It has not been forthcoming."

No. 3 US retailer Target disclosed the theft of some 40 million payment card numbers and the personal data of 70 million customers in a cyber attack that occurred over the holiday shopping season. Neiman Marcus last week said that it too was victim of a cyber attack, and sources have told Reuters that at least three other well-known national retailers have been attacked..

The document noted that an underground market for malicious software to attack point-of-sale, or POS, terminals has flourished in recent years. Three of the most popular titles for the malicious software include BlackPOS, Dexter and vSkimmer.

"We believe there is a strong market for the development of POS malware, and evidence suggests there is a growing demand," the report, obtained by Reuters, warned.

The Secret Service, which is heading up the investigations into the cyber attacks, has declined to comment on what it has learned or identify victims besides Target and Neiman Marcus.

ARMED WITH INFORMATION

John Watters, chief executive of the security intelligence firm iSIGHT Partners, which helped draft the document released on Thursday, said that the government decided to provide information to retailers so they can determine whether their systems have been compromised by hackers.

"The point of getting the technical artifacts out there is that people can go out there and examine their systems and see if they have been compromised," said Watters, whose firm has helped the Secret Service in its investigations of retail breaches. "Now they are armed with information and they can go do something about it."

A Department of Homeland Security official said the report was drafted to provide the industry "with relevant and actionable technical indicators for network defense."

The document said that an advanced piece of software dubbed the POSRAM Trojan, was used in the recent attacks.

POSRAM is an type of RAM scraper, or memory-parsing software, which enables cyber criminals to grab encrypted data by capturing it when it travels through the live memory of a computer, where it appears in plain text.

While the technology has been around for many years, its use has increased in recent years as retailers have improved their security, making it more difficult for hackers to obtain credit card data using other approaches.

POSRAM succeeded in evading detection by anti-virus software when it infected the Windows-based point-of-sales terminals, according to the report.

"This report was generated so that we could get it into the hands of commercial entities so that they had information they needed to protect themselves," iSIGHT Partners Senior Vice President Tiffany Jones told Reuters.

The document was prepared by the Department of Homeland Security's National Cybersecurity and Communications Integration Center, the US Secret Service, iSIGHT Partners and the Financial Sector Information Sharing and Analysis Center, an industry security group.

Alperovitch of CrowdStrike said that the report contained fewer technical details than an article published on Wednesday by security blogger Brian Krebs.

8.03K
 
Hot Topics
The Party vowed on Wednesday to fight corruption firmly and to maintain its "high-handed posture" in the next five years.
...
...
主站蜘蛛池模板: 国产成年女一区二区三区 | 99视频在线看观免费 | 富二代精品视频 | 99久久综合给久久精品 | a大片久久爱一级 | 国产精品久久久久久麻豆一区 | 三级国产在线观看 | 午夜视频国产 | 久久99久久99精品免观看 | 亚洲狠狠狠一区二区三区 | 手机在线国产精品 | 韩国一级性生活片 | 成人18免费观看的软件 | 一本大道香蕉大vr在线吗视频 | 久久www免费人成看国产片 | 一本色综合 | 一级aaaaa毛片免费视频 | 97超级碰碰碰久久久观看 | 国内国外精品一区二区 | 澳门一级毛片手机在线看 | 精品一区二区三区四区在线 | 日韩一级特黄毛片在线看 | 欧美韩国xxx | 久香草视频在线观看 | 亚洲综合色一区二区三区小说 | 视频一区欧美 | 男女男精品视频网站在线观看 | 中文成人在线视频 | 亚洲美女视频网站 | 最全精品自拍视频在线 | 久久久亚洲欧洲日产国码二区 | 欧美成人亚洲国产精品 | 九九九九精品视频在线播放 | 91一区二区在线观看精品 | 国产一区二区三区精品视频 | 91青青国产在线观看免费 | 白嫩美女一级毛片免费看 | 成人免费公开视频 | 欧美日韩中文一区二区三区 | 成年免费大片黄在线观看一 | 精品欧美一区二区三区精品久久 |