Wednesday, November 19, 2008

The number of hacking attacks on computers in the city rose dramatically in the first ten months of the year.

Speaking at the Information Security Summit, Hong Kong Productivity Council executive director Wilson Fung said far government agencies had handled more than 480 attacks during January-October, a 44 percent jump from last year.

He said the alarming rise in attacks demanded government action to raise public awareness and put into place stronger policy measures.

HK Computer Emergency Response Team Coordination Center manager Roy Ko said many attacks came from international cyber-crime syndicates lead by highly trained hackers.

He said the increase was also due to the proliferation of new software more susceptible to attacks.

posted @ 1:08 PM | Feedback (0)

Systems at Barts and the London NHS Trust have fallen victim to a computer virus.

The Trust, which covers three hospitals - St Bartholomew's in the City, The Royal London in Whitechapel and The London Chest in Bethnal Green - said the hospitals' have adopted manual backup systems as a result of the infection.

From the NHS Care Records Service, to the Picture Archiving and Communications System (Pacs)

According to the Trust, "well-rehearsed emergency procedures have been activated" and "key clinical systems continue while network access is being established".

A spokesman for the Trust said the virus was first detected yesterday afternoon, after which the Trust's IT department put in measures to counter the attack.

"At the close of business we thought it was contained but when staff logged on again in the morning, we found it was more widespread than we thought. The network was overloaded," he told silicon.com.

Some computing systems remain offline but for the most part patient services are unaffected.

While some non-essential services at the hospitals were trimmed, A&E, operating theatres and outpatients' departments remained open.

Ambulances are being temporarily diverted to neighbouring hospitals the Trust said. Patients with appointments at the hospital should attend as normal and the Trust has opened a helpline for urgent patient queries on 0207 943 1335.

posted @ 1:06 PM | Feedback (0)

An operating system used in military fighter planes has raised the bar for system security as a new commercial offering.

After receiving the highest security rating by a National Security Agency (NSA)-run certification program, Green Hills Software has announced that its Integrity-178B operating system was certified as EAL6+ and that the company had spun off a subsidiary to market the OS to the private sector as well as government agencies.

"[EAL6+] is the highest [rating] in the world [given to an OS so far today]. This means that the OS was designed and certified to defend against well-funded and sophisticated attackers," says David Chandler, CEO of Integrity Global Security, the new Green Hills subsidiary.

Windows and Linux, meanwhile, are EAL 4+ certified, which means they can defend against "inadvertent and casual" security breach attempts, Chandler says. Integrity-178 B meets the rigorous Common Criteria Separation Kernel Protection Profile (SKPP) standard, which guarantees that malicious code can't corrupt or harm any other application running on the system.

"I'm delighted that they have accomplished this," said Stephen Hanna, co-chair of the Trusted Computing group and distinguished engineer with Juniper Networks, during his keynote at the CSI 2008 conference in National Harbor, Md., Tuesday. "This is serious security."

The OS, which was first deployed in the B1B bomber in 1997, today runs in military and commercial aircraft, including the F-16, F-22, and F-35 military jets, and the Airbus 380 and Boeing 787 airplanes. "It was developed for the highest level of security and reliability," Chandler says. "It's designed to provide a separation, so that what's happening in one area of the computer will not hurt the other part of the OS."

Popular operating systems, such as Windows, Linux, and MacOS, can run atop Integrity-178B, basically as virtual "guests" on the OS, while Integrity runs in hardware. Each operates in its own partition so that if one area is compromised, it can't spread to other areas of the system. "If a hacker got in past the firewall, intrusion detection system, and through Linux," he couldn't get anywhere else in the system, Chandler says.

The OS can run as the sole OS or on servers and clients running Windows, Linux, MacOS, Solaris, and VxWorks, as well as on Palm OS and Symbian PDA's.

Why go commercial now with the hardened OS? Integrity's Chandler says enterprises have been ready for "quite some time" for a more secure operating system. The system and its associated integration and consulting services are custom solutions, says Chandler, who declined to reveal pricing details for that reason.

But whether enterprises will have room in their budgets for hardening their OS environments is unclear as the global financial crisis worsens.

Chandler maintains that locking down the OS saves money for security in the long run. "There's an opportunity that this [solution] could be a cost savings for enterprises, with all that is spent on intrusion prevention" and other security tools and efforts, he says.

Meanwhile, Neil MacDonald, vice president and fellow at Gartner, says partitioning is key to ensuring the security of data and represents the foundation of Gartner's Adaptive Security Infrastructure vision. "Security software running on the same physical machine as the workloads and information it is protecting can't be unequivocally trusted without strong isolation, high assurance, and resiliency of the software," he says.

posted @ 1:05 PM | Feedback (0)