A Warning about Zero-Day Vulnerability
A zero-day vulnerability is an exploit hackers are using to gain access to your information. They are in software, operating systems, browsers, and through your gateway to the Internet. A zero-day, also called zero-hour, is a security flaw in the code that cybercriminal can use to access your network. Zero-day means it’s a security flaw that has not been discovered by the programmers and the makers the products. There is no known fix, and by the time hackers attack, the damage is already done, before it can be patched.
In one day, cybercriminals can attack your network and access your information, taking you down before you can stop them.
Texas-based NSS Labs stated that boutique exploit providers like Endgame Systems, Exodus Intelligence, Netragard, ReVuln and VUPEN can sell more than 100 zero-day exploits in a year. Its research director, Stan Frei, commented that the average zero-day exploit could last for 312 days before it is detected. If this is true, these exploit providers probably provide access to at least 85 zero-day exploits on any given day of the year.
Ponemon Institute conducted a study on behalf of HP Enterprise Security reports that cyber crime costs on average $12.7 million for US companies, and it takes about 45 days to resolve a cyber attack.
A lot of zero-day vulnerabilities don't hit the mainstream media. Most companies don't want their customers to know they have been hacked. However, with zero-day vulnerabilities contained in programming code, the growth of cybercriminals accessing this security flaw is on the rise.
Recent Known Zero-Day Vulnerability
- Sandworm (Microsoft OS kernel vulnerability) attack, targeted SCADA systems used a zero-day vulnerability: Microsoft fixed the error with a patch after the fact. However, while fixing that bug, they also found two other bugs in the code.
- Adobe Flash Player zero-day exploit: Patches were promptly released for Windows, Mac, and Linux operating systems.
- Internet Explorer Watering Hole Exploit: A vulnerability targeted IE 10 users visiting a malicious website.
- Malicious Java script code targeted IE users
- JavaScript-based PDF vulnerabilities
The largest Zero-day exploit in the last year was Heartbleed, a vulnerability in the OpenSSL cryptographic software library. If you're curious, you can read about SeaCat's interesting encounter with Heartbleed. It seems like we detected it and stopped it from entering our systems.
It's not surprising that today like everyone else, zero-day has gone mobile. Thus, when we designed and built our flagship product, SeaCat Mobile Secure Gateway, we made sure that we addressed this kind of vulnerability.
Implement whitelisting: By using a whitelist, only authorized users can access to your internal resources. SeaCat uses a whitelist to allow access only to permitted mobile application instances.
Restrict access: It's recommended to restrict direct access from the Internet to your internal network by setting up an in-between demilitarized zone (DMZ). You limit access from the Internet to the DMZ, the DMZ to the internal network, and so on. This move can block an attacker’s access to an unpatched vulnerability. SeaCat Gateway sits on your DMZ and acts as a shield, filtering in only authorized mobile clients.
Whitelisting and access restriction are just two small built-in defense mechanisms that come with SeaCat. Of course, SeaCat provides much more. Please check out the full product feature list.
If you're in the mobile enablement business, we love to connect with you. Send us an email at info@teskalabs.com or tweet to us TeskaLabs.
Photo credit: Instant Vantage via Imagecreator
Most Recent Articles
- A beginner-friendly intro to the Correlator for effective cybersecurity detection
- Inotify in ASAB Library
- From State Machine to Stateless Microservice
- Entangled ways of product development in the area of cybersecurity #3 - LogMan.io
- Entangled ways of product development in the area of cybersecurity #2 - BitSwan
You Might Be Interested in Reading These Articles
The Two Real Challenges of the Internet of Things
Every week there is a new connected device on the market. A few days ago Tag Heuer launched its smartwatch with Google, and last week I saw a €39 sleep tracker in my supermarket plaster section. Tech conferences are buzzing about the Internet of Things (Consumer Electronics Show 2015, Pioneers Festival 2015).
Published on November 24, 2015
Application Security Issues for HTML5-based Mobile Apps
HTML is no longer restricted to just websites. With its latest edition, HTML5, the markup language family has now become a popular choice for mobile applications. After gathering the relevant data and researching, Gartner predicted two things; firstly, HTML5 would be the most commonly used language for mobile applications in 2015 and secondly, HTML5-based hybrid mobile app using technologies such as PhoneGap, Codova or React Native reach up to be 50% of all mobile apps 2016.
Published on March 01, 2016
Google has introduced new rules about how mobile app developers and companies deal with customer impact on apps across the board. What is it?
The new regulations call for increased transparency with regards to how apps make use of customer data. Developers need to ensure that the way they handle user data - from how they collect it to what it might be used for - is perfectly clear to all users. In Google’s words, developers must “limit the use of the data to the description in the disclosure”. In layman’s terms, this means that data use and privacy policies need to be clearly visible on app descriptions in the Google Play store, and not simply within the app itself.
Published on October 10, 2017