Friday, July 10, 2020

Patrick Chambet, IT security architect and security expert at Bouygues Telecom

The concept of enterprise architecture, very fashionable these days, has a more general framework than traditional technical architecture. It models the business of the company and its processes. He is urbanizing his information system and helping to extend the process to the technical architecture. In summary, it brings a more global vision and builds on the functional areas of the business, in addition to the resources of the IT department. It takes into account in particular the organization, business processes, governance, global architecture, IT production and security.


What is security architecture

The safety architect alongside the chief architect
The security architecture is fully integrated into the overall architecture of the IS. At Bouygues Telecom, the RSSI also works within the ISD itself, in the governance, tools and architecture department, alongside the chief architect. This promotes close relationships between IS security and the central architecture. It also helps to design the target architecture of the IS by integrating the security elements contributing to the common objective of quality of service. Security is therefore an integral part of the overall architecture of the IS. It also provides traditional perimeter security services (network filtering architecture, firewalls, DMZ, VPN, etc.) and defense in depth (trusted spaces, access controls at resource level, detection of intrusion, etc.), several building blocks of infrastructure in the form of shared services. For example, identity and authorization management, authentication directories (Active Directory, LDAP), enterprise PKI, IS access platforms for external partners, secure file transfer service with the outside, etc. More concretely, security spans the entire architecture of the IS. Security requirements are therefore an integral part of the design of the various systems and the applications constituting it. In this context, the technical architects who design the applications must respect the good practices formalized in the security standards of the company's IT developments.

Assess the risk on each IS brick
The relations between the technical architects and the security architect come up against differences in vocabulary, which must be clarified first, by offering them initial training in the concepts of security, in particular in application. Once the common language is assimilated and the first reflexes acquired, the dialogue is much more constructive, because the various stakeholders better understand the risks which weigh on the various systems composing the IS (and therefore on the business processes based on those -this). They also measure the security needs necessary in order to limit these risks to an acceptable level (without even having to address the ISO 27001 standard). The company's IS is increasingly being extended to its partners, including publishers who very often request contractual access to external maintenance for their products installed at the heart of the IS, including in production. This constitutes a significant risk that the adapted and particularly secure access architectures must cover: network filtering, encryption of flows, individual authentication, protocol breaks, enhanced traceability. For all these reasons, taking security into account in the design of the enterprise architecture is already completely essential. individual authentication, protocol breaks, enhanced traceability. 

Thursday, July 9, 2020

Database administrator

Portrait of the profession
The database administrator is responsible for the design of these databases, their implementation, their protection and their procedures for use. He also oversees the management and operation of data and database software while ensuring their integration and efficiency. He works closely with analysts and designers due to their related tasks.

This profession is for you if: Information security architect salary

 You have excellent oral and written communication skills in French and English
 You show leadership
 You are skilled in interpersonal relationships
 You have a good sense of organization
 You have team spirit
 You have a sense of listening
 You find it easy to adapt to a constantly changing sector
 You have good math skills
The tasks and responsibilities that await you :

 Ensure the design, configuration and operation of data and database software, while ensuring constant service to users.
 Develop data backup and recovery systems.
 Provide solutions to data management problems and ensure the optimization of databases.
 Ensure, on the one hand, compliance with methods and standards and, on the other hand, data protection and processing.
 Work in collaboration with users, advise them and offer them support in the use of databases.
Median salary 1

$ 69,400

Required diploma or educational path
Several combinations of studies and experiences can be taken into consideration to enter this profession:

 Bachelor of Computer Science, Computer Science or Math
Or

 Other university degree
Or

 College studies in computer science combined with relevant experience
Or

 Equivalent
Professional experience or sector

Generally speaking, companies are looking for people with two years of experience or less for this type of job. The database administrator is considered an entry position in an organization: we usually start with this function, then we move to another computer position requiring more experience.

Wednesday, July 8, 2020

SOC Cybersecurity System Architect

WHAT WE CAN ACHIEVE TOGETHER:
You join an integrated team already in place (shared between Gennevilliers, the Labège site and our client's site in Toulouse), in a multicultural environment. Your position is based on our Labège site.

Upon arrival, you will follow cybersecurity and space-oriented training upon your arrival and tutoring is in place to assist you in taking up your position.

Your main missions: Network security architecture

Participate in the definition of the architecture of the security monitoring solution for the Galileo system and meet the growing security needs of a critical system at European level.

Propose and justify innovative technical solutions and choices (architecture, technology, system modeling)

Ensure a consistent definition of technical functions, taking into account the system life cycle, deployment and operational use;

Work in multidisciplinary teams and interface with Thales internal cooperants or outside the Group.

Accompany our client and ESA in technical discussions with the various stakeholders on the Galileo system (ESA, European Commission, Industrials) to validate the technical feasibility.

Tuesday, July 7, 2020

How 5G accompanied the fight against coronavirus in China

In the Middle Kingdom where it is operational, 5G has demonstrated its potential in many areas such as health, education and transport.
At the center of many controversies, especially for public health issues (while the latest studies on the subject show that there is no danger ), 5G is nevertheless a lever for transformation in this sector. A lever that has been activated in countries where this new mobile standard is operational, in particular during the coronavirus epidemic.

This technology has been particularly effective in curbing the pandemic, especially in China where it is operational. As the Idate (digital think thank) observes in a study, "5G has proven to be perfectly timely to deal with the coronavirus". Because 5G is not just more speed on your smartphone.

Telemedicine and teleconsultations have been used to curb the pandemic, as many "accelerated" services thanks to the speed and low latency of 5G.

Connected robots and medical imaging chief security architect
But it is especially in hospitals that it has proved most useful with connected robots and covered with biometric sensors capable of establishing precise diagnoses or even capturing images or videos.

We have thus been able to see in China connected robots embedding thermal imaging systems, portable X-rays as well as ultrasonic solutions. 5G then makes it possible to transmit these often very heavy medical images directly.

Idate cites the example of Wuhan and Tianyou Union hospitals attached to the Wuhan University of Science and Technology, which have used 5G intelligent robots supplied by China Mobile and the company CloudMinds. These robots dedicated to patients with Covid-19 disease can take body temperature, disinfect the premises, distribute medicines and meals and can also self-disinfect.

Slowing down the pandemic is also a question of reactivity in informing citizens. Again, 5G has proven useful since it allows live broadcasting in 4K or 8K HD quality and even the use of augmented and virtual reality in the affected areas.

Distance learning and virtual classes
"5G also allows the transmission of videos via a multitude of devices and cameras and has made it possible to broadcast live press conferences devoted to controlling the epidemic in Hubei province," says Idate.

Another area of ​​application is education. As we know, confinement caused the closure of schools and the establishment of distance courses. Where wired networks are not very high-quality, 5G has enabled high-quality video retransmissions and immersive classes in augmented and virtual reality, in particular operated by the giant China Mobile "particularly involved in the development of distance learning solutions".

5G has also been used to manage patient transport flows by collecting real-time information on vehicles and tracking connected vehicles.

In short, according to Idate, fortified by these experiences, "5G could make it possible to approach a new crisis of this type much more serenely. Indeed, from the first announcements of containment, all the activities likely to be carried out have been switched online and the disease has confirmed the opportunities for 5G applications that have already been anticipated. It has demonstrated the benefits of connectivity and network coverage in all activities of life by mitigating the measures of social distancing applied during confinement ". 

Monday, July 6, 2020

NIS Assessment - NIS Directive and Legislative Decree on cybersecurity

The decree applies to Essential Services Operators (OSE) and Digital Service Providers (FSD). The OSE are the subjects, public or private, that provide essential services for society and the economy in the health, energy, transport, banking, financial market infrastructures, drinking water supply and distribution and infrastructures sectors. digital. FSDs, on the other hand, are the legal entities that provide e-commerce, cloud computing or search engine services, with their main establishment, registered office or designated representative on the national territory. Both the "OSE" and the "FSD": Architectural job descriptions

they are called upon to adopt adequate and proportionate technical and organizational measures for risk management and to prevent and minimize the impact of accidents affecting the security of networks and information systems, in order to ensure continuity of service.
have the obligation to report, without undue delay, accidents that have a significant impact (according to the individual definitions of the reference sector), respectively on the continuity and on the provision of the service, to the Italian Computer Security Incident Response Team (CSIRT), also informing the competent NIS reference authority.
DNV GL can support both subjects in pursuing compliance with the requirements of the NIS Directive, which are mandatory and also punishable. The addendum to the decree implementing the NIS, in fact, the dl of 21 September 2019, n. 105 which deals with the "Urgent provisions concerning the cybernetic national security perimeter", establishes the penalties for failure to comply with regulations which are particularly significant: eg. failure to comply with the obligations to prepare and update the list of networks, information systems and IT services referred to in paragraph 2, letter b), is punished with an administrative fine of between € 200,000 and € 1,200,000.
What are the advantages of a verification by DNV GL?
A verification by DNV GL is useful for identifying the limits of an organization's cyber security programs, supporting it in the prioritization of objectives and in the path taken to obtain complete compliance with mandatory legislation, by identifying the level current compliance with current requirements and best industry best practices. The main benefits deriving from third-party and independent evaluations help companies to answer crucial questions, concerning:
what losses can be catastrophic for the organization;
how long the organization can last;
what information cannot end up in the wrong hands;
what is the role of the organization in the socio-economic system;
what damage would cause serious disruption by the organization.
The implementation of a Cyber ​​Risk Management process is crucial for organizations because, to date, it can make the difference between success and failure for a cutting edge company.
What types of companies does it apply to?
The areas of competence are:
Energy sector - Electricity, gas and oil subsectors
Digital infrastructure sector
Digital services
Transport sector - Air transport, rail transport, water transport and road transport sub-sectors
Banking sector
Financial market infrastructure sector
Healthcare sector
Drinking water supply and distribution sector
The DNV GL methodology
DNV GL makes its experience available to companies in the field of process analysis and risk assessment to guarantee the achievement of compliance objectives through a methodological approach that follows
Verification and analysis of the main critical assets and processes, underlying the essential services
Verification of risk analyzes (process, outsourcing, IT, OT) for each identified process / asset
Verification of the classification and mapping of the detected risks to assess their degree of consistency with the exposure
Business Impact Analysis assessment (focused on the consequences of higher value risks
Assessment of the action plan to mitigate the heat
Evaluation of the contents in relation to the tables of the National Framework provided for the specific OSE / FSD Guidelines

Friday, July 3, 2020

Ransomware masquerades as COVID-19 tracking app and ESET creates decryptor

The new ransomware, called CryCryptor, has been targeting Android device users in Canada. The malware has been spreading across two websites, pretending to be an official COVID-19 case tracking app provided by Health Canada. ESET researchers analyzed the ransomware and created a decryption tool for victims.

CryCryptor appeared just a few days after the Canadian government officially announced its intention to support the development of a (voluntary) tracking application for the entire national territory called “COVID Alert”. The official app will be released under test in the province of Ontario next month.

ESET informed the Canadian Cybersecurity Center of this threat as soon as it was identified.

One of the websites used to distribute this malicious app. The other site is identical in design and only differs in domain name, which is covid19tracer Ca.

Once the user is a victim of CryCryptor, the ransomware encrypts the files on the device (the most common types of files) but instead of blocking the computer, it leaves a “readme” file that contains the attacker's email address in each directory containing encrypted files.

Fortunately, we were able to create a decryption tool for those who are victims of this ransomware.

After detecting a tweet that brought this ransomware to our radar (the researcher who discovered it mistakenly classified the malware as a banking Trojan), we analyzed the application. We discovered a bug of the type "Incorrect export of Android components" that MITER labels as CWE-926 .

Due to this failure, any application that is installed on the affected device can start any exported service provided by the ransomware. This allowed us to create the decryption tool , an app that runs the decryption functionality incorporated by its creators into the ransomware app.

Encryption / functionality
After being started, the ransomware requests to access the files on the device. Once you get that permission, it encrypts files with certain extensions, like the ones shown in Figure 2.


File extensions encrypted by ransomware

Files selected by the threat are encrypted using AES with a randomly generated 16-character key. After the CryCryptor ransomware encrypts one file, three new files are created and the original file is deleted. The encrypted file has the extension " .enc ", and the algorithm generates a salt for each encrypted file, which is stored with the extension " .enc.salt "; and an initialization vector, " .enc.iv ".


Files after encryption

After encrypting the files, CryCryptor displays a message that says "Encrypted personal files, see readme_now.txt". The readme_now.txt file is placed in every directory that contains encrypted files.


File encryption notification (left) and file content readme_now.txt (right)

Decoded
The service responsible for decrypting files in CryCryptor has the encryption key stored in the shared preferences, which means that you do not have to contact any C&C to retrieve it. It is important to note that the service is exported without restrictions in the Android Manifesto ( CWE-926 ), which means that it can be started externally.

With this in mind, we created a decryption application for those affected by CryCryptor ransomware on Android. Naturally, the decryption application only works in this version of CryCryptor ransomware.

A new family of ransomware
CryCryptor ransomware is based on open source code on GitHub. We discovered it there by performing a simple search based on the name of the application package and some strings that seemed to be unique.

The developers of the open source ransomware, which they called CryDroid, must have known that the code would be used for malicious purposes. In an attempt to make the project appear in the repository as an investigation, they claim they uploaded the code to the VirusTotal service. Although it is not clear who uploaded the sample, the reality is that it appeared in VirusTotal the same day the code was published on GitHub it architect roles and responsibilities.


Open source ransomware

Likewise, we dismiss the claim that the project is for research purposes: No responsible researcher will publicly release a tool that is easy to use for malicious purposes.

We notify GitHub about the nature of this code.

ESET products provide protection against CryCryptor ransomware, which they detect as Trojan.Android/CryCryptor.A. In addition to using a quality security solution for mobile devices, we recommend Android users to install applications only from reliable sources, such as the Google Play store.

Wednesday, July 1, 2020

Description of tasks and responsibilities - Security architect

The purpose of this mandate is:
Under the supervision of the Chief Director, IT Security and the Senior Director, Architecture, Practice and Technologies, the security architect provides the framework, the directions, the solutions and the support for IT initiatives and security, ensuring the security of the company's IT systems.

More specifically, he / she:
- Supports IT solution architects, designers and delivery teams to ensure that business systems and technological solutions are delivered are secure and aligned with the principles and rules of architecture security;
- Participates as a security expert in reviews of solution architectures and design files for various IT projects;
- Produces security solutions architectures and supports design and integration teams until delivery;
- Assists IT security and architecture managers in the development and application of security guidelines, principles and standards;
- Contributes to risk assessment activities and the development of a mitigation plan architect job duties.


Job Requirements - Security Architect

Experience
- Seven years or more of professional experience in computer security;
- Experience in integrating security measures into business solutions;
- Experience in security architecture, design and integration of security solutions.

Knowledge and skill
- Knowledge of security architecture;
- Ease of understanding business issues and integrating them into the development of solutions or control measures;
- Good knowledge of security technologies and ability to produce functional and technological architecture;
- Knowledge of concepts and solutions for securing cloud services and mobile technologies;
- Knowledge of SDLC processes, Agile delivery method, DevOps;
- Good understanding of internal and network protocols, operating systems, and current technologies;
- Understanding of the principles of cryptography;
- Strong ability to solve problems, identify solutions and follow up until resolved;
- Collaborative approach and excellent interpersonal skills and oral and written communication (English and French);
- Spirit of synthesis and capacity for popularization;
- Dynamism, pragmatism and passion for the field;
- Integrity and professionalism.

Assets
- Certification CISSP, CISA, CISM, CCSP, GIAC or other relevant;
- Knowledge of technological environments Microsoft, Cisco, VMware, CheckPoint, Symantec, Splunk, CrowdStrike, etc .;
- Knowledge of security concepts in cloud (Azure, Office365, AWS, etc.) and mobile (iOS, Android, AirWatch) environments;
- Knowledge of the financial sector and investment;
- Experience in international companies.