Tag Archives: government

Singapore rolls out high-level cyber security strategy

The Government is taking decisive steps to tackle cyber threats – including almost doubling the proportion of its technology budget dedicated to plugging security gaps in critical infrastructure. The matter, said Prime Minister Lee Hsien Loong yesterday, is one of “national importance” as the country becomes more connected in its mission to become a smart nation. At the opening of the inaugural Singapore International Cyber Week, he announced a high-level national strategy that includes strengthening international partnerships. One key prong will be to direct more funds into defence against attacks. These have ranged from malware infection to the defacing of government websites. About 8 per cent of the infocomm technology (ICT) budget will now be set aside for cyber security spending, up from about 5 per cent before. In fiscal 2014, Singapore spent $408.6 million on cyber security. The new proportion is similar to what other countries spend; Israel stipulates that 8 per cent of its total government IT budget must go to cyber security, while South Korea channels as much as 10 per cent. “We are investing more to strengthen government systems and networks, especially those that handle sensitive data, and protect them from cyber attacks,” said Mr Lee. “Singapore aspires to be a smart nation. But to be one, we must also be a safe nation,” he told more than 3,000 public servants and technology professionals from 30 countries who were also attending the 25th GovernmentWare Conference. Singapore’s cyber security strategy is developed by the Cyber Security Agency (CSA). Central to the strategy is the introduction of a new Cybersecurity Act in the middle of next year after public consultations, expected to be held after the draft legislation is tabled in Parliament next year. There is currently no over-arching cyber security legislation in Singapore. The current system of working with various sector regulators is “patchy”, said CSA chief executive David Koh, as the requirement to tighten gaps in critical infrastructure has not been worked into licensing conditions in some sectors. Mr Lee said that, while ICT creates business opportunities and boosts productivity, it also makes its users vulnerable. Globally, cyber threats and attacks are becoming more frequent and sophisticated, with more severe consequences, he added. Last December, a successful attack on the power grid in Ukraine left many Ukrainians without electricity for hours. This year, thieves siphoned US$81 million (S$111.3 million) from the Bangladesh Bank, the central bank of Bangladesh, in a sophisticated cyber heist. Singapore has not been spared. “Our government networks are regularly probed and attacked,” said Mr Lee, adding that attacks included “phishing” attempts and malware infection. “From time to time, government systems have been compromised; websites have been defaced. We also suffered concerted DDOS (distributed denial of service) attacks that sought to bring our systems down,” he said. The financial sector, for instance, has suffered DDOS attacks and leaks of data. Individuals, too, have become victims of scams. Fake websites of the Singapore Police Force, Manpower Ministry, Central Provident Fund Board, and the Immigration and Checkpoints Authority have been set up overseas to “phish” for personal information or trick people into sending money. Mr Lee said the country must get cyber security right. “Only then can IT deliver innovation, growth and prosperity for our businesses and citizens.” Source: http://www.straitstimes.com/singapore/spore-rolls-out-high-level-cyber-security-strategy

Visit site:
Singapore rolls out high-level cyber security strategy

SANS issues call to arms to battle IoT botnets

Do try this at home – but carefully The SANS Institute is hoping sysadmins can help it to do what vendors won’t: improve Internet of Things security.…

See the original post:
SANS issues call to arms to battle IoT botnets

Source code unleashed for junk-blasting Internet of Things botnet

Hackforums leak Malicious code used to press-gang IoT connected devices into a botnet was leaked online over the weekend.…

Taken from:
Source code unleashed for junk-blasting Internet of Things botnet

No wonder we’re being hit by Internet of Things botnets. Ever tried patching a Thing?

Akamai CSO laments pisspoor security design practices Internet of Things devices are starting to pose a real threat to security for the sensible part of the web, Akamai’s chief security officer Andy Ellis has told The Register .…

More:
No wonder we’re being hit by Internet of Things botnets. Ever tried patching a Thing?

Security man Krebs’ website DDoS was powered by hacked Internet of Things botnet

Internet of Amazingly Insecure Tat? That’s the one The huge distributed denial of service (DDoS) attack which wiped security journalist Brian Krebs’ website from the internet came from a million-device-strong Internet of Things botnet.…

Originally posted here:
Security man Krebs’ website DDoS was powered by hacked Internet of Things botnet

Google rushes in where Akamai fears to tread, shields Krebs after world’s-worst DDoS

600 Gbps traffic flood overwhelmed CDN Google has provided free distributed denial of service attack (DDoS) mitigation services to security publication Krebs on Security , stepping in after Akamai withdrew support.…

Continue reading here:
Google rushes in where Akamai fears to tread, shields Krebs after world’s-worst DDoS

IBM botched geo-block designed to save Australia’s census

Bureau of Stats says spooks signed off IBM’s plan, but Big Blue mucked something up Australia’s Bureau of Statistics has heavily criticised IBM for the security it applied to the nation’s failed online census, which was taken offline after a distributed denial of service (DDoS) attack that battered a curiously flimsy defensive shield.…

See more here:
IBM botched geo-block designed to save Australia’s census

DDoS attacks: For the hell of it or targeted – how do you see them off?

Cloud-based DDoS defences introduce delays Distributed Denial of Service (DDoS) attacks can be painful and debilitating. How can you defend against them? Originally, out-of-band or scrubbing-centre DDoS protection was the only show in town, but another approach, inline mitigation, provides a viable and automatic alternative.…

Taken from:
DDoS attacks: For the hell of it or targeted – how do you see them off?

Infected Android phones could flood America’s 911 with DDoS attacks

One killer trojanised app or $100k of hardware is enough. A research trio has shown how thousands of malware-infected phones could launch automated distributed denial of service attacks to cripple the US emergency phone system “for days”.…

Visit site:
Infected Android phones could flood America’s 911 with DDoS attacks