Since the pandemic there has been a race to go digital, organisations and individuals alike. Remote working, remote learning, contactless payments, and online shopping has become the mainstay of our lives. While technology really helped us get through the pandemic, it came with a learning curve, the lack of awareness about dos and donts made many easy targets for hackers and hacking organisations. The rush to go digital exposed a lot of companies to cyber-attacks through ransomware, data breaches, and leaks. The Pegasus and Predator scandals also showed us that hacking now is a business and Politicians are also using the services of these companies for their own benefit. As technology moves ahead, the risk of cyber-attacks increases as well, to explain a bit more about the current cyber security scenario Siddharth Shankar from TimesNow speaks to Asaf Hecht, from CyberArk. Asaf manages one of the research groups in CyberArk Labs. He focuses on researching and discovering the latest attack techniques and applying lessons learned to improve cyber defenses. Prior to CyberArk, Asaf served for eight years in the Israeli Army, as a skilled helicopter pilot and as Team Leader for the advanced cyber-hunting team, an elite force that protects military top-secret networks and reveals APTs.
Excerpts
Asaf: You are absolutely correct about the situation during COVID, We saw it in the entire world that people and organization go on digital and work from home like me today, and everything is going for the internet and there is also a paradigm shift. The legacy of the traditional perimeter is finished. When you have a company and you are in a physical building, you can secure this building with what is going out and where is the entrance and exit.
Nowadays, everything is everywhere, and this is the need of the hour. The trends that you mentioned are correct. Also, contactless payment is also gaining popularity in countries like Israel. From bigger organizations to private ones to even individuals. From the youngest who thrive to use new technology to older people that don't have other options because the bank or store in the neighborhood was closed because it converted online. However, there are a few things that we need to remember regarding the outlook toward risk, it's different from the organisation side and different from the individual side of things.
For individuals, I think awareness is important to everyone and every age. Having said that, I think there are some principles that are very important.
For example, check your bank account and your credit card payment at least once per month. This is because there is a high chance of these kinds of things occurring without your knowledge. If you get scammed and phished and someone stole your credit card and pays for his desire. The most important thing for you is to detect it and then you can automatically alert the credit card company and also you will get a full refund from credit card company. The first principle, again simple awareness. The second principle is to check what goes out from your accounts and submit it for refund if something is wrong.
The third principle, the normal public is not the target, this is a big difference between attacks on organisations and attacks on individuals. While I believe threat actors can attack everyone, everything, and every device, it is only a matter of how much time is consumed, the budget and what are they gaining out of it. I can imagine myself if I have a phone and I don't think someone will want access to my phone, and it will offer him $10,000. I am sure it's not. There is nothing important there.
Siddharth - Phishing and getting money out of people or crypto wallets are quite common, but lately, we have been seeing a lot of state-sponsored threat actors and we have also been seeing private companies which are actually working only on finding exploits, finding zero-day hacks and then selling it to governments and making a big chunk of money. So now this is probably becoming a business as well and a lot of them actually stem from Israel. What are your thoughts on this? Is this quickly becoming a business prospect for hackers?
Asaf - I think it's an interesting trend and I agree with it. In the recent decade, there are few private companies that are mentioning that they do is to develop technology solutions for gaining access and intelligence. I think that in Israeli Cyber intelligence, getting cyber intelligence or getting cyber access to a device or target, has been around for over two decades, and then what happened is the people who were in the army service, some of them completed their service and they still wanted to do what they did. Also, we need to remember that most of the usage of these technologies is for humanitarian reasons for anti-terror fighting and for making sure there is no major terror attack. The fact is that for 20 years, we didn't have a devastating terror attack again (in Israel). And I think a major thing that helped this fact apart from other countermeasures is their demonstration is this kind of spying technologies that sometimes also comes from the private sector.
The challenge and the problem emanate from how you make sure that these kinds of technologies are being handled and sold to the right target. This is a problem, but these are the two sides of things. The world I think needed this kind of spying company to make it a safer place, but the problem from the other side is how to monitor and who these companies sell to and even if they sell it to a government, maybe the government will say, yeah. We are going to use it on a valid target, but I think these private companies don't really can audit, the usage of this third-party government.
Siddharth - Back in 2011, Bill Gates had said that the next big challenge for the world will not be a nuclear war, it would be a virus. We had COVID and the whole world just stopped. Do you think in the future, a full blown war like the Russia-Ukraine conflict will not happen and it will be more cyber warfare?
Asaf - I think there are more challenges, but I think cybersecurity issues are gaining more value because more assets are converting to be online and again, our daily things are online, and sometimes even from the army's perspective, its easier to do something behind the keyboard and not blast anyone and risk your people going to war, I think it's a future threat. While saying it, I think it's also there is a balance thats kind of the nuclear balance that both of the sides have nuclear power, so no one uses it. I think it might go to this one. Maybe the country could devastate the other country in the cyber war, but I think they understand that there might be attacks on the same power as well. It might be a threat that is above our head, but not really will be done with 100% power. I do think and we already saw that in a low power cyber attacks already happening right? Also, even in Ukraine and Russia conflict, Russia on the starting day of the conflict, wiped out hundreds of machines and denial of services attacks on websites in Ukraine and so on.
Siddharth - Asaf now lately, we have seen Predator, we have seen ERMAC, Follina, and a lot of other malware or ransomware coming out. Why is this happening? We have the internet the knowledge is there, and the news spreads. Yet all these things are happening so much more today than say 5 to 10 years ago.
Asaf - Yes, with the popularity of the internet and technologies and phone devices and everything is computerized, and I think that awareness and even the availability of knowledge is very easy to gain for everyone.
As an example, the lapsus$ or phishing attack, will still probably work. It is really a problem, but again we should sleep well, there are cybersecurity vendors out there doing our best. For example, at CyberArk, we try to help organizations across the world and so it will be harder for attackers to achieve their goal also if they attack a company, the damage will be reduced a lot. They will not be at a total loss, and we also see this from the other side of your question, we see more attacking groups yes, and ransomware campaigns because they have money and there are more options for people and also to build an organization and a business. As an example, there is Conti, an attacking group that does ransomware mainly. It's built like a regular company, there is human resources, HR, there is R&D, and there is a kind of marketing to make the tool available to a paying audience. Yeah, this is kind of the new world.
Siddharth - You mentioned the supply chain attacks. Now if the supply chain is crippled for a big company like say Samsung or Apple. It is going to cause a lot of damage and damage reduction will be the biggest thought once the attack has happened. What are the things they should keep in mind before an attack happens and after an attack happens to minimize the damage to them and their consumers?
Asaf - Before the attack happens, we should make sure that our network is there in the most secure place and in the most secure state. There are many protocols and steps and standards. One of the main things is to secure privileged access security and secure identity security. Nowadays, it's not only devices and laptops and phones, but also more of the identity that uses this computer in this form because it could be many identities on the same device, and multiple identities or specific identities could be accessing across multiple devices. We need to secure the focus on identity. How it has been authenticated, what it does and there are again many solutions that can help with this. I would focus on securing the identities and of course making sure to check all the standards.
If we do the preparation right in stage 1, the damage will be limited because one identity will be compromised and one network will be compromised, but the sensitive database is on a different network and there is a segmentation in the network, and so on. If we did the preparation right then the damage should be limited, but still, we should also prepare for this compromise because it might happen at any time and we should also practice it. I think most organisations will suffer from this kind or another compromise, but good preparation will limit the damage when it occurs.
Siddharth - What would your forecast be in terms of trends of security that we will be seeing in the future, like supply chain is one, next what could be it?
Asaf - Interesting question. I think cloud will be major as nowadays cloud is a popular for the technology benefits and so on and I think now that cloud services are being used much more, the attacks on this kind of scenario will be more popular. Some unique specific services like database on cloud and SQL on cloud and virtual machine on cloud and things like this.
Another thing I might say is the attacks in the future will be about machine learning and automation around attacking and automation around the discovery of vulnerabilities, open source is also a popular vector because nowadays because technology is so complex, we have several components on every product. Open source is also another vector.
Siddharth - During WWDC, Apple announced something about a passwordless feature. Do you think this is an interesting concept that will increase security?
Asaf - Yes. There are several disadvantages of having a password. Of course, its hard to remember, people tend to use the same password for 2 different services and so on. The trend of a passwordless future, I think it's good. Mainly it involves some other device or multifactorial with your phone. The passwordless thing is a good solution, From our vulnerability research, we saw after the authentication has been successfully done, it's still a token or digital token or certificate that is being stored in the computer and a device in the cloud. After the authentication phase, the token is not really authenticated more. Nowadays there is a new trend of continuous authentication. You want to continuously authenticate the identity and what it does.
Continued here:
Cyber-attacks in future will be about machine learning and automation around attacking and discovery of vulner - Times Now
- What Is Machine Learning? | How It Works, Techniques ... [Last Updated On: September 5th, 2019] [Originally Added On: September 5th, 2019]
- Start Here with Machine Learning [Last Updated On: September 22nd, 2019] [Originally Added On: September 22nd, 2019]
- What is Machine Learning? | Emerj [Last Updated On: October 1st, 2019] [Originally Added On: October 1st, 2019]
- Microsoft Azure Machine Learning Studio [Last Updated On: October 1st, 2019] [Originally Added On: October 1st, 2019]
- Machine Learning Basics | What Is Machine Learning? | Introduction To Machine Learning | Simplilearn [Last Updated On: October 1st, 2019] [Originally Added On: October 1st, 2019]
- What is Machine Learning? A definition - Expert System [Last Updated On: October 2nd, 2019] [Originally Added On: October 2nd, 2019]
- Machine Learning | Stanford Online [Last Updated On: October 2nd, 2019] [Originally Added On: October 2nd, 2019]
- How to Learn Machine Learning, The Self-Starter Way [Last Updated On: October 17th, 2019] [Originally Added On: October 17th, 2019]
- definition - What is machine learning? - Stack Overflow [Last Updated On: November 3rd, 2019] [Originally Added On: November 3rd, 2019]
- Artificial Intelligence vs. Machine Learning vs. Deep ... [Last Updated On: November 3rd, 2019] [Originally Added On: November 3rd, 2019]
- Machine Learning in R for beginners (article) - DataCamp [Last Updated On: November 3rd, 2019] [Originally Added On: November 3rd, 2019]
- Machine Learning | Udacity [Last Updated On: November 3rd, 2019] [Originally Added On: November 3rd, 2019]
- Machine Learning Artificial Intelligence | McAfee [Last Updated On: November 3rd, 2019] [Originally Added On: November 3rd, 2019]
- Machine Learning [Last Updated On: November 3rd, 2019] [Originally Added On: November 3rd, 2019]
- AI-based ML algorithms could increase detection of undiagnosed AF - Cardiac Rhythm News [Last Updated On: November 19th, 2019] [Originally Added On: November 19th, 2019]
- The Cerebras CS-1 computes deep learning AI problems by being bigger, bigger, and bigger than any other chip - TechCrunch [Last Updated On: November 19th, 2019] [Originally Added On: November 19th, 2019]
- Can the planet really afford the exorbitant power demands of machine learning? - The Guardian [Last Updated On: November 19th, 2019] [Originally Added On: November 19th, 2019]
- New InfiniteIO Platform Reduces Latency and Accelerates Performance for Machine Learning, AI and Analytics - Business Wire [Last Updated On: November 19th, 2019] [Originally Added On: November 19th, 2019]
- How to Use Machine Learning to Drive Real Value - eWeek [Last Updated On: November 19th, 2019] [Originally Added On: November 19th, 2019]
- Machine Learning As A Service Market to Soar from End-use Industries and Push Revenues in the 2025 - Downey Magazine [Last Updated On: November 26th, 2019] [Originally Added On: November 26th, 2019]
- Rad AI Raises $4M to Automate Repetitive Tasks for Radiologists Through Machine Learning - - HIT Consultant [Last Updated On: November 26th, 2019] [Originally Added On: November 26th, 2019]
- Machine Learning Improves Performance of the Advanced Light Source - Machine Design [Last Updated On: November 26th, 2019] [Originally Added On: November 26th, 2019]
- Synthetic Data: The Diamonds of Machine Learning - TDWI [Last Updated On: November 26th, 2019] [Originally Added On: November 26th, 2019]
- The transformation of healthcare with AI and machine learning - ITProPortal [Last Updated On: November 26th, 2019] [Originally Added On: November 26th, 2019]
- Workday talks machine learning and the future of human capital management - ZDNet [Last Updated On: November 26th, 2019] [Originally Added On: November 26th, 2019]
- Machine Learning with R, Third Edition - Free Sample Chapters - Neowin [Last Updated On: November 26th, 2019] [Originally Added On: November 26th, 2019]
- Verification In The Era Of Autonomous Driving, Artificial Intelligence And Machine Learning - SemiEngineering [Last Updated On: November 26th, 2019] [Originally Added On: November 26th, 2019]
- Podcast: How artificial intelligence, machine learning can help us realize the value of all that genetic data we're collecting - Genetic Literacy... [Last Updated On: November 28th, 2019] [Originally Added On: November 28th, 2019]
- The Real Reason Your School Avoids Machine Learning - The Tech Edvocate [Last Updated On: November 28th, 2019] [Originally Added On: November 28th, 2019]
- Siri, Tell Fido To Stop Barking: What's Machine Learning, And What's The Future Of It? - 90.5 WESA [Last Updated On: November 28th, 2019] [Originally Added On: November 28th, 2019]
- Microsoft reveals how it caught mutating Monero mining malware with machine learning - The Next Web [Last Updated On: November 28th, 2019] [Originally Added On: November 28th, 2019]
- The role of machine learning in IT service management - ITProPortal [Last Updated On: November 28th, 2019] [Originally Added On: November 28th, 2019]
- Global Director of Tech Exploration Discusses Artificial Intelligence and Machine Learning at Anheuser-Busch InBev - Seton Hall University News &... [Last Updated On: November 28th, 2019] [Originally Added On: November 28th, 2019]
- The 10 Hottest AI And Machine Learning Startups Of 2019 - CRN: The Biggest Tech News For Partners And The IT Channel [Last Updated On: November 28th, 2019] [Originally Added On: November 28th, 2019]
- Startup jobs of the week: Marketing Communications Specialist, Oracle Architect, Machine Learning Scientist - BetaKit [Last Updated On: November 30th, 2019] [Originally Added On: November 30th, 2019]
- Here's why machine learning is critical to success for banks of the future - Tech Wire Asia [Last Updated On: December 2nd, 2019] [Originally Added On: December 2nd, 2019]
- 3 questions to ask before investing in machine learning for pop health - Healthcare IT News [Last Updated On: December 8th, 2019] [Originally Added On: December 8th, 2019]
- Machine Learning Answers: If Caterpillar Stock Drops 10% A Week, Whats The Chance Itll Recoup Its Losses In A Month? - Forbes [Last Updated On: December 8th, 2019] [Originally Added On: December 8th, 2019]
- Measuring Employee Engagement with A.I. and Machine Learning - Dice Insights [Last Updated On: December 8th, 2019] [Originally Added On: December 8th, 2019]
- Amazon Wants to Teach You Machine Learning Through Music? - Dice Insights [Last Updated On: December 8th, 2019] [Originally Added On: December 8th, 2019]
- Machine Learning Answers: If Nvidia Stock Drops 10% A Week, Whats The Chance Itll Recoup Its Losses In A Month? - Forbes [Last Updated On: December 8th, 2019] [Originally Added On: December 8th, 2019]
- AI and machine learning platforms will start to challenge conventional thinking - CRN.in [Last Updated On: December 23rd, 2019] [Originally Added On: December 23rd, 2019]
- Machine Learning Answers: If Twitter Stock Drops 10% A Week, Whats The Chance Itll Recoup Its Losses In A Month? - Forbes [Last Updated On: December 23rd, 2019] [Originally Added On: December 23rd, 2019]
- Machine Learning Answers: If Seagate Stock Drops 10% A Week, Whats The Chance Itll Recoup Its Losses In A Month? - Forbes [Last Updated On: December 23rd, 2019] [Originally Added On: December 23rd, 2019]
- Machine Learning Answers: If BlackBerry Stock Drops 10% A Week, Whats The Chance Itll Recoup Its Losses In A Month? - Forbes [Last Updated On: December 23rd, 2019] [Originally Added On: December 23rd, 2019]
- Amazon Releases A New Tool To Improve Machine Learning Processes - Forbes [Last Updated On: December 23rd, 2019] [Originally Added On: December 23rd, 2019]
- Another free web course to gain machine-learning skills (thanks, Finland), NIST probes 'racist' face-recog and more - The Register [Last Updated On: December 23rd, 2019] [Originally Added On: December 23rd, 2019]
- Kubernetes and containers are the perfect fit for machine learning - JAXenter [Last Updated On: December 23rd, 2019] [Originally Added On: December 23rd, 2019]
- TinyML as a Service and machine learning at the edge - Ericsson [Last Updated On: December 23rd, 2019] [Originally Added On: December 23rd, 2019]
- AI and machine learning products - Cloud AI | Google Cloud [Last Updated On: December 23rd, 2019] [Originally Added On: December 23rd, 2019]
- Machine Learning | Blog | Microsoft Azure [Last Updated On: December 23rd, 2019] [Originally Added On: December 23rd, 2019]
- Machine Learning in 2019 Was About Balancing Privacy and Progress - ITPro Today [Last Updated On: December 25th, 2019] [Originally Added On: December 25th, 2019]
- CMSWire's Top 10 AI and Machine Learning Articles of 2019 - CMSWire [Last Updated On: December 25th, 2019] [Originally Added On: December 25th, 2019]
- Here's why digital marketing is as lucrative a career as data science and machine learning - Business Insider India [Last Updated On: January 13th, 2020] [Originally Added On: January 13th, 2020]
- Dell's Latitude 9510 shakes up corporate laptops with 5G, machine learning, and thin bezels - PCWorld [Last Updated On: January 13th, 2020] [Originally Added On: January 13th, 2020]
- Finally, a good use for AI: Machine-learning tool guesstimates how well your code will run on a CPU core - The Register [Last Updated On: January 13th, 2020] [Originally Added On: January 13th, 2020]
- Cloud as the enabler of AI's competitive advantage - Finextra [Last Updated On: January 13th, 2020] [Originally Added On: January 13th, 2020]
- Forget Machine Learning, Constraint Solvers are What the Enterprise Needs - - RTInsights [Last Updated On: January 13th, 2020] [Originally Added On: January 13th, 2020]
- Informed decisions through machine learning will keep it afloat & going - Sea News [Last Updated On: January 13th, 2020] [Originally Added On: January 13th, 2020]
- The Problem with Hiring Algorithms - Machine Learning Times - machine learning & data science news - The Predictive Analytics Times [Last Updated On: January 13th, 2020] [Originally Added On: January 13th, 2020]
- New Program Supports Machine Learning in the Chemical Sciences and Engineering - Newswise [Last Updated On: January 13th, 2020] [Originally Added On: January 13th, 2020]
- AI-System Flags the Under-Vaccinated in Israel - PrecisionVaccinations [Last Updated On: January 22nd, 2020] [Originally Added On: January 22nd, 2020]
- New Contest: Train All The Things - Hackaday [Last Updated On: January 22nd, 2020] [Originally Added On: January 22nd, 2020]
- AFTAs 2019: Best New Technology Introduced Over the Last 12 MonthsAI, Machine Learning and AnalyticsActiveViam - www.waterstechnology.com [Last Updated On: January 22nd, 2020] [Originally Added On: January 22nd, 2020]
- Educate Yourself on Machine Learning at this Las Vegas Event - Small Business Trends [Last Updated On: January 22nd, 2020] [Originally Added On: January 22nd, 2020]
- Seton Hall Announces New Courses in Text Mining and Machine Learning - Seton Hall University News & Events [Last Updated On: January 22nd, 2020] [Originally Added On: January 22nd, 2020]
- Looking at the most significant benefits of machine learning for software testing - The Burn-In [Last Updated On: January 22nd, 2020] [Originally Added On: January 22nd, 2020]
- Leveraging AI and Machine Learning to Advance Interoperability in Healthcare - - HIT Consultant [Last Updated On: January 22nd, 2020] [Originally Added On: January 22nd, 2020]
- Adventures With Artificial Intelligence and Machine Learning - Toolbox [Last Updated On: January 22nd, 2020] [Originally Added On: January 22nd, 2020]
- Five Reasons to Go to Machine Learning Week 2020 - Machine Learning Times - machine learning & data science news - The Predictive Analytics Times [Last Updated On: January 22nd, 2020] [Originally Added On: January 22nd, 2020]
- Uncover the Possibilities of AI and Machine Learning With This Bundle - Interesting Engineering [Last Updated On: January 22nd, 2020] [Originally Added On: January 22nd, 2020]
- Learning that Targets Millennial and Generation Z - HR Exchange Network [Last Updated On: January 23rd, 2020] [Originally Added On: January 23rd, 2020]
- Red Hat Survey Shows Hybrid Cloud, AI and Machine Learning are the Focus of Enterprises - Computer Business Review [Last Updated On: January 23rd, 2020] [Originally Added On: January 23rd, 2020]
- Vectorspace AI Datasets are Now Available to Power Machine Learning (ML) and Artificial Intelligence (AI) Systems in Collaboration with Elastic -... [Last Updated On: January 23rd, 2020] [Originally Added On: January 23rd, 2020]
- What is Machine Learning? | Types of Machine Learning ... [Last Updated On: January 23rd, 2020] [Originally Added On: January 23rd, 2020]
- How Machine Learning Will Lead to Better Maps - Popular Mechanics [Last Updated On: January 30th, 2020] [Originally Added On: January 30th, 2020]
- Jenkins Creator Launches Startup To Speed Software Testing with Machine Learning -- ADTmag - ADT Magazine [Last Updated On: January 30th, 2020] [Originally Added On: January 30th, 2020]
- An Open Source Alternative to AWS SageMaker - Datanami [Last Updated On: January 30th, 2020] [Originally Added On: January 30th, 2020]
- Machine Learning Could Aid Diagnosis of Barrett's Esophagus, Avoid Invasive Testing - Medical Bag [Last Updated On: January 30th, 2020] [Originally Added On: January 30th, 2020]
- OReilly and Formulatedby Unveil the Smart Cities & Mobility Ecosystems Conference - Yahoo Finance [Last Updated On: January 30th, 2020] [Originally Added On: January 30th, 2020]