Thursday, November 7, 2013

Personal Privacy in the Insurance Sector

James E. Gilbert
UMUC
April 11, 2013

Introduction
Privacy, particularly as it pertains to the digital realm, is an essential issue for many Americans.  As individuals use the Internet for an increasing amount of daily activities, safeguarding personal data remains an important component for both consumers and companies.  In an early study, the Markle Foundation found that online privacy was one of the most critical aspects among Internet users, with concern over identity theft limiting some online transactions (Friedman, 2001).  This apprehension persists in the modern era with online privacy legislation debated in the U.S. legislature on a seemingly annual basis.  Among the concerns of Internet users, there are few aspects where privacy is more critical than matters of financial importance.  With more individuals conducting their financial transactions online, the United States government along with the banking sector sought a way to bolster consumer confidence.  Their solution was the Financial Services Modernization Act of 1999, more commonly known as the Gramm-Leach-Bliley (GLB) Act of 1999.  Although the purpose of the GLB Act was to deregulate the financial industry, it also implemented a set of privacy standards pertaining to companies in the banking and insurance sectors.  The following paper assesses the key areas of the GLB Act as it applies to the life insurance market.  Specifically, the privacy policies of three insurance companies (Farmers Insurance Group, Monumental Life Insurance, and Metropolitan Life Insurance) are examined to identify similarities and differences among the companies as well as to provide the basis for recommendations for improvement.

Organizations and Missions
The primary goal of the GLB Act was to lower regulations enacted by the Bank Holding Company Act of 1956 and the Banking Act of 1933.  Legislators envisioned that the act would facilitate a stronger financial sector by allowing companies to diversify across industries.  In effect, the GLB Act encouraged banks, securities firms, and insurance companies to expand into each other’s sectors.  The legislation also facilitated mergers between companies within the different areas of the financial services sector (Neale, Drake, & Clark, 2010).  The GLB Act helped shaped some of most recognizable insurance companies in the modern era.

Farmers Insurance Group
Formed in 1928 in California as the Farmers Automobile Inter-Insurance Exchange, modern day Farmers is one of America’s largest insurers.  Started with a handful of employees by entrepreneurs, John C. Tyler and Thomas E. Leavey, the company now boasts 74,000 career and independent agents.  Farmers insures over 10 million households representing 20 million individual policies, with customers in all 50 states (About Farmers, 2013).  Although the company primarily insures homes, automobiles, and small businesses, they also offer a variety of other insurance and financial services products. Farmers and its subsidiaries are wholly owned by the Zurich Insurance Group Ltd (Farmers Insurance, 2013).

Monumental Life Insurance
Although the modern day company has gone through a number of transformations, Monumental Life Insurance can trace its origins back to 1858 when it became Maryland’s first life insurance company (Monumental, 2010).  According to Hoovers (2013), the company offers life insurance, long term care, accident and health insurance, and retirement products through a blended workforce of career employees and independent agents.  In 1986, Monumental was acquired by the Dutch insurance company, Aegon.  In 2011, Aegon USA announced that its subsidiaries would conduct all transactions solely under the umbrella name, Transamerica (Monumental, 2010).  Transamerica primarily offers life insurance, retirement and investment products.  The company has over 14 million customers throughout the United States and is licensed in every state except New York and DC (Transamerica, 2013).

Metropolitan Life Insurance
Founded in 1868, the Metropolitan Life Insurance Company is a subsidiary of MetLife, Inc.  Headquartered in New York, the company became a global insurer after their 2010 acquisition of the American Life Insurance Company from the American International Group, Inc. (AIG) (Bloomberg BusinessWeek, 2013).  This purchase added to Metropolitan’s customer base giving the firm 90 million customers in over 50 countries (MetLife, 2013).  Metropolitan Life Insurance Company offers individual home, life and accident insurance, retail banking, and various financial and retirement services.  The company also sells retirement and financial services to institutions and corporations.  Metropolitan markets its products directly through agents as well as through third-party banks and brokers (Bloomberg BusinessWeek, 2013).

Privacy Policies
The United States government has a long history of legislative efforts regarding the defense of personal privacy.  One of the key components of this focus has been the protection of personally identifiable information (Hermalin & Katz, 2006).  From the Fair Credit Reporting Act and the Privacy Act in the 1970’s to more current legislation, the importance of this debate persists as increasing amounts of personal data are moved into the digital realm.  Safeguarding this information and reassuring consumers remains an important matter for both public and private organizations.  In the American economy, there are few areas where protection of this information is more critical than the financial sector.  Although the final version of the GLB Act outlines privacy rules that financial institutions must abide by, the original draft of the bill made no mention of this topic.  It was not until the bill was presented to the House Commerce Committee that the issue of privacy in the financial sector became such a politically active issue that this subject was added to the final legislation (Friedman, 2001). 

Title V of the GLB Act specifically addresses the privacy protections afforded to consumers regarding their financial information.  This provision pertains to “non-public personally identifiable financial information” to include data provided by the consumer as well as information collected or obtained by the institution (Friedman, 2001, p. 3).  Persons conducting business with a financial company must receive notice of their privacy rights with special considerations provided based on the relationship an individual has with an institution. For instance, in the GLB Act a “customer” is defined as someone with a continuing relationship with a company while a “consumer” has obtained a financial product but is considered a short-term client.  This distinction is important because “customers” receive privacy notices annually while “consumers” only receive them if their information is shared with a non-affiliated firm.  In either case, notices “…must be a clear, conspicuous, and accurate statement of the company’s privacy practices; it should include what information the company collects about its consumers and customers, with whom it shares the information, and how it protects or safeguards the information” (FTC, 2002, p. 2).  Lastly, a company’s privacy policy should also afford individuals with a method to “opt-out” of having their personal information shared with unaffiliated third parties.  This section must explain that consumers have the right to limit the disclosure of their data and provide reasonable means to remove their names from this process (FTC, 2002).  Although the GLB Act mandates certain legally enforceable guidelines, not all privacy policies are created equal with a number of similarities and differences existing among firms.

Similarities
Since the GLB Act was passed in 1999, financial companies have had over ten years to implement the legislation. Of the companies assessed (Farmers, Monumental and Metropolitan), all three had identifiable privacy policies conspicuously displayed on their corporate websites.  The firms clearly outlined the purpose of their policies and who the notices pertained to.  All three companies clearly detailed what types of information was collected and who it was disclosed to.  Each company mentioned in varying degrees of detail how electronic information such as cookies and IP addresses were also collected.  Finally, all three companies listed some level of detail pertaining to the safeguards their firms had in place to protect consumer privacy.

Differences
Two years after the GLB Act was passed, the Center for Democracy and Technology (CDT) conducted a survey of 100 financial institutions to determine their level of policy implementation completed.  The Center found a widely varying array of legislative application on the part of institutions (Friedman, 2001).  The majority of the differences stemmed from digital services, a discrepancy that could be explained by the relative newness of online financial transactions.  Since then, the Internet and information technology has evolved considerably; although discrepancies among corporate policies is still evident.

Although Farmers, Monumental and Metropolitan each had a section in their privacy policy regarding digital safeguards, the level of detail provided differed among firms.  The Metropolitan policy only discussed defenses in generalized terms, while Farmers went the additional step to mention their company uses 2048-bit encryption (Farmers Privacy Policy, 2011).  Monumental had the most comprehensive security section which discussed areas such as access controls and electronic transactions.  Another area that differed among the companies surveyed had to do with the “opt-out” clause.  In addition, only two of the insurance companies assessed (Farmers and Metropolitan) had conspicuously displayed this section in their privacy notices.  No such “opt-out” clause was evident in Monumental’s privacy policy (Monumental Privacy Statement, 2012).

Recommendations
Since the GLB Act was ratified in 1999, developments in the field of consumer privacy have revolved around “…maintaining a healthy balance between the need for free and open information sharing and the importance of protecting customers’ privacy rights domestically and abroad” (Roach & Schuerman, 2005, p. 439).  Although many corporations worry about the government’s role in this arena, Hermalin and Katz (2006) found that privacy policies can be improved to better protect consumer’s rights as well as become more efficient and flexible for corporations.  For this bill to remain relevant in the modern era, supporters of online privacy believe updated legislation is required.

Farmers Insurance Group
According to the FTC, an individual’s right to prohibit having their information shared with other companies must be offered in a reasonable manner.  Examples of this can consist of opting out via a toll-free number or online form.  A case of an unreasonable method would be to require the customer or consumer to write a letter to the firm (FTC, 2002).  Although the Farmers’ privacy notice includes a toll-free number to call, doing so then initiates a separate form mailed to the requestor.  In the modern era, the argument could be made that not being able to complete this activity completely over the phone or even having an online option could constitute an unreasonable method.  A 2004 study conducted by six federal agencies surveyed 110 financial institutions about various implementation aspects of the GLB Act.  One of the topics these agencies researched was the effectiveness of “opt-out” procedures among the companies.  What they determined was that a more efficient system was needed.  One of the proposed solutions included a default “opt-out” policy for all consumers with a centralized repository similar to the National Do Not Call Registry (SEC, 2009).  This would provide consumers with increased control over their privacy rights, while streamlining the process for institutions.

Of the three companies examined, Farmers provided an average level of detail regarding their firm’s cybersecurity.  Although the GLB Act does not dictate the amount of information a financial firm must provide, offering more data could help alleviate individual’s concerns as well as allow them to make more informed decisions regarding which financial firm to choose.  Full disclosure in this area however must be balanced with the firm’s need for digital security.  Too much information disclosed could provide hackers with enough information to facilitate attacks against the company’s digital infrastructure.

Monumental Life Insurance
Although Monumental provided the most detail regarding their security practices, this was the only area sufficiently developed.  In addition to not having a conspicuous opt-out procedure, Monumental also had the shortest privacy notice.  Although the GLB Act does not advocate a specific format, this area has long been a source of contention between the financial industry and government regulators, with companies allowed to develop their own policies.  As late as 2009, federal agencies observed an assortment of privacy notices varying in the amount of information delivered to consumers.  Some institutions have argued that having excessively lengthy notices may confuse clients and actually run contrary to the GLB Act’s “clear and conspicuous” requirement (SEC, 2009).  The solution to this dilemma may lie somewhere in the middle.  Institutions should be provided with a general framework for their firm’s privacy notices, but be allowed to modify the policy as necessary.  This would give companies both guidance and flexibility, which could provide customers with clearer privacy notices and allow companies to better adhere to federal regulations.

Metropolitan Life Insurance
While Metropolitan provided the least amount of information about their security procedures, the company provided an excessive amount of detail regarding their policy on information sharing.  This portion of Metropolitan’s notice goes so far as to say that “even if you opt-out, however, any MetLife company fortunate enough to have you as a customer may continue to send you information about products and services offered by any of our affiliated or unaffiliated companies” (MetLife Privacy Policy, 2009).  While this may not strictly violate privacy rights covered under the GLB Act, in effect this statement amounts to MetLife’s ability to send their customers endless amounts of spam correspondence. This raises a question first discussed in 2001, of the glaring exceptions to information sharing within the GLB Act.  Proponents of consumer privacy feel portions of the act goes too far, with the CDT arguing that consumers should also be provided the ability to opt-out of public information sharing for marketing purposes.  This recommendation would provide consumers with a greater control over their personal privacy.

Conclusion
Privacy is a core tenet of the Gramm-Leach-Bliley Act, having increased consumer awareness in the financial services sector (FTC, 2002).   Although this act is important legislation, compliance does not always equate to adequate customer protection however.  Almost 15 years after being enacted, there still exists a wide array of privacy notices among companies.  Accordingly, a number of individual states have begun to view the legislation as ineffective and have passed their own versions of the law.  Often times, the outcome of this results in more stringent and state-specific requirements that companies must follow. As a result, adhering to the spirit of the GLB Act could prove advantageous for the financial industry as a whole.  Ensuring privacy notices are clearly and accurately written protects institutions from potential liability issues.  Although a standardized format for this notice may be too simplistic for some firms, a list of best practices could provide adequate guidance to allow for both consumer protection and organizational flexibility.

References
About Farmers. (2013). Farmers Insurance Group. Retrieved from http://www.farmers.com/farmers_insurance.html

Bloomberg Business Week. (2013). Company overview of Metropolitan Life Insurance

Farmers Insurance. (2013). Farmers Insurance to celebrate 85th anniversary by joining forces
with Feeding America to conduct national food drive as way to continue giving back to communities it serves (Press Release). Retrieved from http://www.marketwatch.com

Farmers Privacy Policy. (2011). Farmers Insurance Group. Retrieved from

Federal Trade Commission (FTC). (2002). In brief: The financial privacy requirements

Friedman, A. (2001). Online banking privacy: A slow confusing start to giving customers control
over their information. Center for Democracy and Technology. Retrieved from http://www.ftc.gov/bcp/workshops/glb/supporting/CDTonlinebanking.pdf

Hermalin, B., & Katz, M. (2006). Privacy, property rights and efficiency: The economics of
privacy as secrecy. Quantitative Marketing & Economics, 4(3), 209-239. doi:10.1007/s11129-005-9004-7

Hoovers. (2013). Monumental Life Insurance Company: Company profile. Retrieved from


MetLife Privacy Policy. (2009). Metropolitan Life Insurance Company. Retrieved from

Monumental. (2010). History. Retrieved from https://www.monlife.com/ML/history.asp

Monumental Privacy Statement. (2012). Monumental Life Insurance Company. Retrieved from

Neale, F. R., Drake, P. P., & Clark, S. P. (2010). Diversification in the financial services
industry: The effect of the financial modernization act. The B.E. Journal of Economic Analysis and Policy: Topics in Economic Analysis & Policy, 10(1), 1-28. Retrieved from http://www.degruyter.com/view/j/bejeap

Roach, S. R., & Schuerman Jr., W. R. (2005). Privacy year in review: Recent developments in
the Gramm-Leach Bliley Act, Fair Credit Reporting Act, and other acts affecting financial privacy. I/S: A Journal of Law and Policy for the Information Society, 1(2-3), 385-440. Retrieved from http://moritzlaw.osu.edu/students/groups/is/

Securities and Exchange Commission (SEC). (2009). Final model privacy form under the
Gramm-Leach-Bliley Act. Retrieved from http://www.sec.gov/rules/final/2009/34-61003.pdf

Transamerica. (2013). About us. Retrieved from http://www.transamerica.com/about_us/





2011 Cyberattack on DuPont

James E. Gilbert
UMUC
March 30, 2013

Introduction
According to a 2011 white paper published by the computer security firm Symantec, security analysts identified an effective and well-coordinated cyber threat primarily directed against the American private sector (Chien & O'Gorman, 2011).  Codenamed "Nitro", the attack initially targeted human rights organizations and automotive manufacturers as early as April 2011.  Although 48 companies across a wide range of industries were affected, by July 2011 the focus of the cyberattack shifted solely to organizations in the chemical sector.  29 companies from this industry were affected with DuPont among the most heavily targeted (Prince, 2011).  As one of the world’s largest chemical manufacturers, DuPont holds lucrative patents including Teflon and Kevlar (DuPont, 2013).  It is this type of intellectual property that researchers believe was the intended target for industrial spies.  This incident is representative of a growing type of cyberattack commonly known as advanced persistent threats (APT). 

By their very nature, APTs are carried out by countries or organizations with the resources and knowledge to launch coordinated and prolonged cyberattacks on protected networks.  Groups that employ APTs generally target companies or government agencies seeking lucrative intellectual property or classified government information.  The motivations for the type of attack DuPont experienced range from financial to geopolitical and the threat actors have been known to use a variety of methods to gain entry into hardened networks.  To combat this growing danger, organizations must adopt a defense-in-depth methodology to cybersecurity that not only protects digital infrastructure but also discourages future attacks.

Threat Category
The first APT was seen as early as 1998, when analysts identified a series of cyberattacks against the Pentagon, NASA and the US Department of Energy.  It has only been in the last few years however that this innovative threat has been used with increasing frequency and effectiveness (Smiraus & Jasek, 2011).  Each part of the name “Advanced Persistent Threat” represents important characteristics of this threat category.  APTs are advanced in that they represent an innovative and adaptive cyberattack.  Actors employing this approach are well-versed in a variety of technical and non-technical exploitations to gain entry into a targeted network.  They use publicly available hacking tools or can utilize more sophisticated techniques depending on the level of network defenses.  APTs are persistent in that targets are carefully researched and the attack meticulously planned.  Actors using this approach often require prolonged access to their targets and have the capability to exploit a network for months or even years to obtain intended information.  Finally, APTs are carried out by a special category of hackers.  Individuals generally lack access to the technical and personnel resources necessary to carry out these attacks.  The majority of APTs identified are estimated to have been carried out by nation-states or criminal organizations (Scully, 2011).  Identified by Symantec during the "Nitro" hack, these characteristics are important pieces of information when determining likely attackers (Chien & O'Gorman, 2011). 

Likely Threat Actors
When analyzing what types of attackers could carry out a cybercrime, it is import to assess motivation and means.  While these factors will be discussed in later detail, it is important to note that all that is required for an APT “…is an aggressor with a motive and a few tens of thousands of dollars” (Scully, 2011, p. 200).  This means APTs are available options to corporate adversaries, organized crime groups and hacktivists alike.  Historically however, APTs are forms of attack believed to be carried out by nation-states.  Since 2010, there has been an increasing amount of evidence pointing to China as one of the most active users of this form of cyberwarfare. 

As early as 2006, McAfee began tracking a five-year long cyber campaign called Operation Shady.   The intrusion targeted over 70 public and private organizations throughout 14 nations (McDonald, 2011).  In a more recent example, the security encryption firm RSA was hacked in 2012.  Experts believe the culprits used the information they obtained to carry out additional attacks against the defense contractor Lockheed Martin.  Based on a growing database of techniques and motives, experts believe the culprit behind both attacks and the 2011 attack on the chemical sector to be hackers located in China (McDonald, 2011).

Motivation
Historically, APT attacks have targeted private industry trade secrets or classified government data.  Attacker’s motivations have included political activism, economic espionage, or traditional warfare (Chien & O'Gorman, 2011).  APTs are used in these cases, because this type of information is often stored within well-protected networks.  As a result, hackers seeking this data must resort to a prolonged and sophisticated approach to attack  targeted networks.  Over the last few years, hackers have penetrated the networks of defense contractors, computer chip manufacturers, and mining companies.  The type of information exfiltrated has ranged from blueprints to chemical formulas (Riley, 2012). 

As one of the world’s largest and oldest pioneers of industrial chemicals, DuPont invests a significant amount of revenue in research and design activities.  This is evident by the company’s product page which boasts over 1,400 new products and 2,000 filed patents (DuPont, 2013).  Over the last few years, government agencies and corporate security firms alike have signaled the warning that China has actively engaged in cyberwarfare for both industrial and traditional espionage purposes. The 2011 attack on DuPont and the chemical sector appears to follow this pattern with the attacker’s goal being “…intellectual property such as design documents, formulas, and manufacturing processes” (Chien & O'Gorman, 2011, p. 1).

Targeted Assets
Although the "Nitro" attack initially targeted human rights organizations and auto manufacturers, the majority of companies affected came from the chemical sector.  This included a number of Fortune 500 companies involved in the development of advanced materials for both corporate and military uses (Chien & O'Gorman, 2011).  The perpetrator behind the intrusions appeared to be after intellectual property from the various chemical companies.  Proprietary information from these companies represents a significant investment in both time and financial resources.  Illicitly obtaining this type of information provides nations or companies with the means to significantly enhance their own research and development activities at a fraction of the cost.  Based on their findings, Symantec’s researchers believe the purpose of the 2011 penetrations to be “industrial espionage, collecting intellectual property for competitive advantage” (McDonald, 2011).

Means of Attack
According to historical analysis, the most prevalent type of APT begins with a social engineering attack (Smiraus & Jasek, 2011).  Hackers used a similar two-pronged tactic against DuPont and other targeted organizations in 2011.  Specific emails were sent to recipients within each company claiming to be from known business associates while a more generalized email was sent to hundreds of random employees appearing to be a security update.  The emails were actually Trojans containing a self-extracting executable file named Poison Ivy.  Poison Ivy is a commonly available Remote Access Tool (RAT) developed by a Chinese national.  Once executed, the program provides an attacker with complete control over a target’s computer.  After installation, the Poison Ivy program contacted a command and control (C&C) server using TCP port 80.  Attackers used the program to gather information about the compromised system including the “infected computer’s IP address, the names of all other computers in the workgroup or domain, and dumps of Windows cached password hashes” (Chien & O'Gorman, 2011, p. 2).  With this information, hackers began exploring the network looking for domain administrator credentials in order to provide them access to computers storing the desired information.  The last part of the attack differed depending on the targeted system.  In most of the cases however, once the attackers gained access to the targeted information, it was copied to internal system archives.  The data was then uploaded to remote servers to finalize the exfiltration and complete the cyberattack.

Description of Attackers
The growing consensus throughout the cybersecurity community is that the Chinese government is one of the most active state sponsors of cyber espionage.  Conclusively proving this theory and identifying specific attackers however has been problematic.  In the DuPont hack, Symantec was actually able to trace the attacks back to a single individual.  This level of detail was obtained by tracking the original attack back to a virtual private server in the United States.  This in turn was connected to an individual known as Covert Grove, who was later identified as a Chinese male in his 20’s living in the Hebei region of China (Chien & O'Gorman, 2011).  Security experts have become increasingly successful at tracing attacks back to specific IP addresses; however proving who was actually behind the attack has been more elusive.  In the 2011 attack on DuPont, Symantec was unable to determine if Covert Grove acted alone or was employed by a third party.  Symantec theorized that the level of expertise needed to carry out the attack suggests Chinese government or military involvement.  This theory however has been difficult to prove.  China has both the largest population of internet users in the world, with some of the poorest security practices (McDonald, 2011).  Even when a hacker’s IP address can be traced backed to mainland China, the Chinese government has plausible deniability in the fact that computers are easily hijacked and IP addresses spoofed (Mandiant, 2013).

How to Discourage Future Incidents
Although the high-profile attack on various chemical companies in 2011 was newsworthy, it was not the first cyberattack targeting DuPont.  In fact, the chemical company was attacked by Chinese hackers twice between 2009 and 2010.  This information was kept secret by DuPont until a separate cyberattack by the hacktivist group Anonymous uncovered confidential emails about the incident and released them to the public (Riley & Forden, 2011).  Not only were these attacks kept secret from the public, but they were also held back from the company’s investors.  DuPont’s 10-K filings with the Securities and Exchange Commission (SEC) during this period failed to even mention cyberattacks as a significant risk to the company (Riley, 2012).  DuPont’s response to this incident has been the typical reaction from most publicly traded companies.  Many organizations believe that any disclosure of cyberattacks may equate to a damaged reputation or a drop in stock price.  Companies believe these negative consequences outweigh any potential benefit from sharing details of the attack and lessons learned with other organizations (Smiraus & Jasek, 2011).   

Compelling companies to be more forthcoming with details of attacks has been sporadic at best.  Federal laws such as the Sarbanes-Oxley Act of 2002 and the Health Insurance Portability Act of 1996 require companies in certain industries to report cyberattacks (Scully, 2011).  Although these regulations require companies to report attacks, the SEC’s interpretation is that the amount of information required to be disclosed “…will depend on whether company lawyers determine the incidents had, or will have, a material effect on the enterprise” (Riley, 2012).  This leaves room for interpretation among companies and across industries.  Many in the cybersecurity community believe however, that disclosure and information exchange are among the most important tools in discouraging future cyberattacks.  This principle was further emphasized by President Obama in February 2013 when he signed a presidential directive outlining information sharing between the public and private sectors on matters of cybersecurity. The executive order takes an innovative approach in that it directs the Department of Homeland Security to share classified cybersecurity threat information with private organizations (Zetter, 2013).   The theory behind this approach is that with relevant threat detail, private companies will have the intelligence and perhaps motivation to better safeguard their digital infrastructure from impending attacks.

How to Defend Against Similar Threats
Information sharing is an important component in protecting against cyberattacks, but it must be used in conjunction with a robust security plan.  A common method  used to better understand what organizational risks exist is the Operationally Critical Threat, Asset, and Vulnerability Evaluation (OCTAVE) framework.  This technique provides organizations with a tool to develop individual threat profiles based on critical assets and vulnerabilities (UMUC, 2013).  In the case of DuPont, security analysts using the OCTAVE technique would have been able to determine that intellectual property was a critical asset to the organization with foreign nations or competing companies interested in obtaining this information.  Employing the OCTAVE framework would also have shown the company's management that a large multinational organization with thousands of employees like DuPont has numerous vulnerabilities.  To defend against attacks similar to the 2011 "Nitro" penetration, DuPont must adopt a comprehensive security strategy that incorporates administrative, personnel and technical safeguards.

A recent assessment found that 128 Fortune 500 companies do not have policies in place protecting their intellectual property (Matthews, 2013).  This means that in over 25% of America's largest corporations, employees have no uniform policy guiding their daily decisions on how to handle some of their organization's most valuable assets.  As cyberattacks and corporate espionage continue to increase in frequency and sophistication, drafting comprehensive security and acceptable use policies should be the first step in creating a defense-in-depth cyber strategy.  Once a policy is in place, organizations should focus on a variety of human and technical safeguards.  Just as most APTs begin with a social engineering attack against individual workers, employees also represent the first line of defense against this threat.  All individuals in a company must be provided with up-to-date security training and awareness briefings on emerging cyber threats.  Finally, critical information assets should be afforded an extra layer of network protection.  Digital architectures should be created to segregate "trophy information" like trade secrets from normal activities within an organization (Scully, 2011).  This includes implementing separation-of-duty policies and safeguards as well as restricting use of unauthorized mobile devices and portable digital media.  In addition, IT administrators should ensure that operating systems and applications are routinely patched and regular system audits are conducted (Smiraus & Jasek, 2011).

Conclusion
APTs, like the one targeting DuPont in 2011, are sophisticated and carefully executed attacks carried out by determined adversaries.  The type of information attackers seek is so financially or strategically valuable, that nations or groups employing these tactics will stop at nothing to obtain it.  To defend against this threat, organizations must adopt defense-in-depth approaches incorporating hardware, software, personnel and policy safeguards.  This strategy should also include information sharing between public and private sectors.  Although APTs are a relatively new phenomenon, one of the most effective strategies in discouraging future incidents has been alerting the public to the tactics and techniques of successful cyberattacks.

References
Chien, E., & O'Gorman, G. (2011). The Nitro attacks: Stealing secrets from the chemical

DuPont. (2013). Company at a glance. Retrieved from http://www2.dupont.com/Our_Company/en_CA/glance/

Mandiant. (2013). APT1: Exposing one China’s cyber espionage units. Retrieved from

Matthews, C. M. (2013). Many companies silent on IP protection as cyber threat emerges. The

McDonald, J. (2011). Cyber attacks on chemical companies traced to China. USA Today. Retrieved from http://usatoday30.usatoday.com/money/industries/technology/story/20111101/China-hackers/51024936/1

Prince, B. (2011). Coordinated cyber attacks hit chemical and defense firms. Security Week.

Riley, M. (2012). SEC push may yield new disclosures of company cyber attacks. Bloomberg.

Riley, M., & Forden, S. (2011). Hacking of DuPont, J&J, GE were Google-type attacks that

Scully, T. (2011). The cyber threat, trophy information and the fortress mentality. Journal of
Business Continuity & Emergency Planning, 5(3), 195-207. Retrieved from http://www.henrystewartpublications.com/jbcep

Smiraus, M., & Jasek, R. (2011). Risks of advanced persistent threats and defense against them.
Annals of DAAAM & Proceedings, 1589-1590. Retrieved from http://daaam.info/?page_id=895

University of Maryland University College (UMUC). (2013). Module 7: Psychological Aspects
of Cybersecurity. CSEC 620: Human Aspects in Cybersecurity: Ethics, Legal Issues, and Psychology. Retrieved from http://tychousa1.umuc.edu

Zetter, K. (2013). Executive order aims to facilitate sharing of information on threats. Wired.




Securing Social Networks

James E. Gilbert
UMUC
March 16, 2013

Introduction
The last few years have seen an extraordinary amount of growth in what’s been referred to as Web 2.0 technologies.  This concept refers to innovative uses of the Internet and is embodied by the phenomenon of social networking sites.  Companies use these tools to promote new products and government agencies employ them for publicity campaigns and recruiting events (Kim, 2012).  An increasing number of organizations allow or even require employees to use these sites on the job.  From Facebook to LinkedIn, more people each year join social networks to connect with friends, collaborate with colleagues, and post an increasing amount of private information online.  By their very nature, social media sites invite users to disclose personal data.  Although the concept of online interaction suggests anonymity, much of this information is openly available for anyone to see and collect.  This opportunity has not escaped the attention of cyberattackers.  From nation-states seeking back doors into government facilities to criminals trolling for credit card numbers, social media has proven to be a major security threat to organizations and individuals alike.  The following paper outlines three of the biggest vulnerabilities inherent to social media sites: Authentication Controls, Web Browsers, and Employees; as well as their corresponding threats.  Finally, mitigation techniques are discussed taking into account organizational policies and procedures that employees are most likely to follow. 

Authentication Controls
Employees of HBGary setting up their display at the 2011 RSA security conference were shocked to find a note in their booth left by the notorious hacker group, Anonymous.  The note and other threats of violence to HBGary’s employees, eventually forced the company to withdraw from the conference (Anderson, 2011).  The battle between the two organizations began the week prior after the CEO of HBGary Federal threatened to release the names of Anonymous members he had collected.  Anonymous responded with a swift and effective attack on the digital infrastructure of HBGary and their affiliate, HBGary Federal.  Key systems of both companies were accessed, causing a significant amount of damage and embarrassment to the company’s reputation as a premier technology security firm.  The potential implication of this type of attack is even more serious considering HBGary Federal provided computer security services to the U.S. federal government.

Vulnerabilities
Although extreme, the cyberattack on HBGary was not groundbreaking.  Anonymous used publicly available techniques to exploit authentication vulnerabilities within HBGary’s network. While the cyberattack on HBGary began with a website vulnerability known as an SQL Injection attack, the majority of the damage was facilitated by inadequate authentication protocols.  Two members of HBGary Federal’s senior management, CEO Aaron Barr and COO Ted Vera, used weak passwords for their corporate accounts and then reused them for their social networking sites.  This provided members of Anonymous with an effective social engineering tool as corporate servers allowed password-based authentication (Bright, 2011).  Inadequate authentication procedures remain a serious vulnerability for organizations relying solely on password-enabled security.  In addition, social networking sites like Facebook and LinkedIn provide rich targets for hackers employing phishing techniques.  This type of attack often utilizes social media to steal passwords through the use of fake logon pages (Bamnote, Patil, & Shejole, 2010).  Even if passwords and usernames cannot be obtained through phishing efforts, users will often post enough personal data online to enable hackers to guess logon information.

Threats
Authentication vulnerabilities on social networking sites are leveraged by virtually every type of cyberattacker.  As membership on social media increases, these sites represent attractive targets to a variety of nefarious groups.  Threats exist from identity thieves and hacktivists to nation-states alike.  Criminals use these pages to steal lucrative personal information.  Nation states troll websites looking for weaknesses into protected networks.  In the case of HBGary, the hacktivist group Anonymous used social media to protest the release of group member’s names. Although they did not seek monetary gain from the attack, the financial damage to HB Gary and its affiliates were still significant.

Likelihood
According to security experts, the probability that illicit groups will continue to circumvent authentication vulnerabilities is high. The Secure Enterprise 2.0 Forum publishes an annual report compiling the details of social media usage of Fortune 500 companies.  In their 2009 report, one of the eight main threats to social media discussed were “insufficient authentication controls” (Chi, 2011).  All too often, employees and organizations choose convenience over security in creating weak passwords and employing single sign-on technologies. This vulnerability is compounded when looking at the amount of actual attacks that take place.  Microsoft’s semi-annual Security Intelligence Report recorded a 1200 percent increase in phishing attacks used on social networks in 2010 (Fisher, 2011).  Ultimately, this threat remains one of the most cost effective methods of illegally acquiring logon information and is estimated to continue increasing in frequency.

Mitigation
To help manage the risk associated with this vulnerability, a combination of policy, training and technology should be employed.  Organizations should ensure they have in place a policy that outlines the authentication requirements for their employees.  This involves educating employees on authentication safeguards such as not reusing passwords and ensuring they are of sufficient strength.  Had HBGary’s executive staff followed such a recommendation, Anonymous would not have been able to gain access to their email accounts.  Companies should also consider technology solutions to protect their authentication information.  Software should be configured to specify password requirements for employees as well as to securely store these secret keys.  HBGary made Anonymous’ job that much easier by storing passwords as MD5 hashes.  A more secure option would have been to use a stronger key like the SHA family of encryption (Thomas, 2011).

Customer Acceptance
Often times, security must be balanced with convenience when it comes to safeguarding digital infrastructure.  Defenses used to protect authentication mechanisms are no exception.  Rather than remember different passwords for each personal and business account, individuals often choose the less secure route.  This involves reusing passwords, picking easily guessed words, or even writing them down.  Organizations seeking to alter this behavior must increase employee awareness on the dangers of such practices.  Ultimately any changes must begin at the top.  If an organization’s leadership is viewed as unsupportive to enhanced security practices, employees will not be motivated to change their behaviors (Cisco Systems, 2008).  As with the case of HBGary Federal, when the CEO and COO do not follow proper authentication measures, how can employees be expected to?

Web Browsers
On November 14, 2011, Facebook users were shocked to receive explicit and violent pictures on their newsfeeds.  Later determined to be a Cross-Site Scripting (XSS) attack, the incident lasted for 24 hours leaving Facebook administrators helpless.  Attackers rely on the sheer number of social media memberships combined with user’s trust of these websites.  This allows them to trick individuals into downloading malicious software or entering personally identifiable information into fake sites (Rashid, 2011).  As more public and private organizations turn to social media to advertise their presence, the risk from this type of attack will continue to increase.

Vulnerabilities
According to the National Security Agency (2009), XSS attacks and malicious content are two of the most pervasive threats to web browsers.  These threats take advantage of vulnerabilities in the software web browsers run on.  Generally, flaws in the host user’s computer are exploited to allow for JavaScript code injections.  This provides hackers with the ability to compromise computer systems in order collect financial or password information or control the system for use in subsequent cyberattacks.  Perpetrators of the 2011 Facebook attack also employed social engineering to create a self-XSS exploit.  This provided hackers with an even more effective attack by further convincing users to enter “…the code necessary to execute the attacks, as opposed to other types of XSS-based attacks where the perpetrators inject the code on to the Website” (Rashid, 2011).

Threats
Attackers incorporating XSS attacks into social media sites have the potential to infect hundreds of millions of users.  Although the Facebook incident seemed purely malicious in nature, XSS attacks generally incorporate some form of financial scam.  While the historic goal is often the collection of personal financial information, this technique can also be used to collect passwords or social engineering data for additional attacks (Nemey, 2011).  From nation-states to criminal enterprises, cyberattackers often seek the path of least resistance into a protected network.  XSS attacks can provide this access into a hardened defense contractor or classified government agency’s computer systems.

Likelihood
The probability that cyberattackers will continue using XSS attacks is high. From private industry to the government sector, this vulnerability routinely makes the list of top organizational risks.  Symantec’s latest Internet Security Threat Report identified compromised hyperlinks on social networking sites as one of the most common threats in 2011.  The report also estimated that with malware authors continuing to increase their use of social networking sites, this trend was estimated to increase even further in 2012 (Symantec, 2012).  Symantec’s report was further reinforced by the secure cloud hosting company, FireHost.  Based on web application statistics, FireHost reported a 160% increase in XSS attacks between the 3rd and 4th quarters of 2012 alone (FireHost, 2013).

Mitigation
With the probability of XSS attacks continuing to increase, social media organizations and users alike should consider a holistic approach to mitigation.  Although Facebook implemented a number of technical safeguards post-attack, individuals using these sites also have a responsibility to protect their information.  Safe message handling and browsing practices are recommended for anyone visiting social media sites.  This involves scrutinizing suspicious messages and hyperlinks prior to opening them (Chi, 2011).  The National Security Agency also recommends a list of technical best practices which includes users installing the latest patches on their operating systems and browsers, updating virus scanners, and installing firewalls or intrusion prevention systems (National Security Agency, 2009).

Customer Acceptance
A 2008 study by Cisco found that employees disregard security procedures because they fail to understand the implications of their actions.  Unless security is an individual’s primary job function, employees do not naturally possess a sense of ownership over shared corporate assets.  These findings show that employees must be motivated to take a staked interest in the defense of their organization’s information technology.  Moreover, because many employees visit personal websites at work, the overlap between personal and business security practices no longer exists.  To combat this apathy, organizations must create effective security policies that are simple enough for customers to utilize.  This involves clearly communicating the security policies and how not adhering to them can affect each worker.  Acceptable use standards and security procedures should be streamlined for maximum compliance and aligned with business processes and job requirements (Cisco Systems, 2008).  Associating performance evaluations and bonuses with security compliance is one way to achieve policy compliance and customer satisfaction.

Employees
Robin Sage was an attractive young woman with an impressive resume of academic and security credentials.  Her profiles on various social networking sites attracted the interest of security professionals working for the NSA, DOD and Fortune 500 companies alike.  After a month online Robin Sage had collected 300 contacts and was offered jobs, speaking engagements, and had been inadvertently provided with operational security (OPSEC) data for various companies and federal agencies.  Unfortunately 28 days later, her contacts were shocked to find out they had fallen prey to a social engineering experiment; Robin Sage never existed.  The creation of security professional Thomas Ryan, Robin Sage was only a fictitious identity and attractive profile picture used to entice security professionals.  As Ryan explains in a Black Hat talk entitled “Getting in bed with Robin Sage”, the experiment was meant to demonstrate the considerable vulnerability that exists from social engineering through networking sites likes Facebook and LinkedIn (Goodchild, 2010).

Vulnerabilities
The Robin Sage experiment exposes one of the biggest and most exploitable vulnerabilities in the field of cybersecurity: Employees.  Generally regarded as the weakest link in the security chain, human error is often responsible for or helps facilitate numerous cyberattacks each year.  Combine this flaw with the misguided tendency to trust social media, and hackers and thieves alike are provided with an effective tool to attack protected networks.  As Ryan points out, some of the most security-minded individuals in the public and private sectors were fooled into delivering a social engineering goldmine.  The haul from LinkedIn alone provided personal email addresses, cell phone numbers, and whether contacts were out of town (Goodchild, 2010).  This information can be exploited by any number of individuals or groups as part of a larger attack on an employee’s organization.

Threats
According to Nemey (2011), two of the biggest threats to social media are social engineers and employees.  Nation-states and criminals alike have used active social engineering tactics to breach hardened networks.  From espionage to financial motivations, hackers often use this approach to leverage employee trust and mistakes.  If this was not a serious enough threat, often times attackers do not even need to resort to such methods.  Passive approaches like the Robin Sage experiment or inadvertent employee disclosures on social media sites can often be collected to provide an attacker with enough information to breach an organization’s digital infrastructure.

Likelihood
The Secure Enterprise 2.0 Forum lists phishing and information leakage as two of the biggest threats posed by social media sites (Chi, 2011).  The likelihood that this trend will continue is high.  With technical defenses advancing as quickly as information technologies, hackers will continuously seek the least defended points of entry into networks; which often involves employee carelessness.  Social engineering attacks through sites like Facebook create an impression of familiarity.  This illusion gives users a false sense of security and provides a medium to post seemingly private information about home and work.  Although these bits of personal data are not necessarily secret, they can be collected into useful components of a cyberattack.

Mitigation
Humans represent both the vulnerability and the safeguard against social engineering attacks through social media.  Although technical safeguards provide some measure of security redundancy, the ultimate defense for this risk is effective policy and training to increase employee awareness.  According to the IT-compliance organization ISACA, “the greatest risks posed by social media are all tied to violation of trust” (ISACA, 2010).  The very nature of social networking encourages the open disclosure of information.  To mitigate this risk, organizations should establish acceptable use and technical security policies.  According to a global security study commissioned by Cisco, many instances of data leakage occur in organizations with ineffective or nonexistent standards (Cisco Systems, 2008).  Effective security policies should include a maximum amount of employee participation, be widely disseminated and they should receive the full support of all management levels within an organization (Kabay & Kelley, 2009).

Customer Acceptance
Finding equilibrium between security and employee access to social media has proven to be a difficult balance for companies in the modern era.  According to a Forrester Research report, companies should consider a number of areas when establishing an acceptable use policy for social media.  This includes deciding what level of access employees need, should individuals be allowed to download software, what information can be posted, and what are the consequences for policy violations (Burnham, 2010).  According to ISACA, any defense against the risks posed by social media usage should begin with employee behavior (ISACA, 2010).

Conclusion
According to the computer security firm Sophos, cybercriminals will continue using social media as a platform to launch cyberattacks for the foreseeable future (Lyne, 2012).  With more organizations allowing employees access to social media from work, the potential for this medium to compromise organizational resources remains a very real threat.  Personal information posted to these sites can be used to deduce corporate passwords, providing hackers with access to otherwise protected networks.  The only way to defend against this risk is a defense-in-depth approach that incorporates technical, personnel, and administrative defenses.  Not only must organizations ensure effective training and policies are in place, but employees must also take a vested interest in protecting shared network assets.  Just as individuals often represent the weakest link in security, they can also become the greatest defense.

References
Anderson, N. (2011). Anonymous vs. HBGary: The aftermath. Ars Technica. Retrieved from

Bamnote, G., Patil, G., & Shejole, A. (2010). Social networking-Another breach in the wall. AIP
Conference Proceedings, 1324(1), 151-153. doi:10.1063/1.3526180

Bright, P. (2011). Anonymous speaks: the inside story of the HBGary hack. Ars Technica.

Burnham, K. (2010). Social media safety: Acceptable-use policies are critical. CIO. Retrieved from http://www.cio.com/article/590113/Social_Media_Safety_Acceptable_Use_Policies_Are_Critical

Chi, M. (2011). Reducing the risks of social media to your organization. SANS Institute

Cisco Systems. (2008). Data leakage worldwide: The effectiveness of security policies.

FireHost. (2013). Cross-site scripting attacks up 160% in final quarter of 2012, reveals FireHost.

Fisher, G. (2011). Phishing, social networking attacks on the rise. Threatpost. Retrieved from

Goodchild, J. (2010). The Robin Sage experiment: Fake profile fools security pros. Network

ISACA. (2010). Top five social media risks for business: New ISACA whitepaper. Retrieved

Kabay, M. E., & Kelley, S. (2009). Computer security handbook (5th ed.). Hoboken, NJ: John Wiley & Sons

Kim, H. J. (2012). Online social media networking and assessing its security risks. International
Journal of Security & Its Applications, 6(3), 11-18. Retrieved from http://www.sersc.org/journals/IJSIA/

Lyne, J. (2012). Year in Review: 2011. Sophos. Retrieved from http://www.sophos.com/en-us/security-news-trends/security-trends/2011-year-in-review.aspx

National Security Agency. (2009). Social Networking Sites. Retrieved from http://www.nsa.gov/ia/_files/factsheets/I73-021R-2009.pdf

Nemey, C. (2011). 5 top social media security threats. Network World. Retrieved from

Rashid, F. Y. (2011). Facebook Pursuing Attackers Who Exploited XSS-Flaw in Massive Spam

The Associated Press. (2012). Number of active users at Facebook over the years. Retrieved

Thomas, K. (2011). 8 security tips from the HBGary hack. PC World. Retrieved from