Qatar

Thousands of viruses ‘pose threat to Mideast financial institutions’

Thousands of viruses ‘pose threat to Mideast financial institutions’

April 23, 2013 | 11:47 PM

(From left) Christiaan Beek of McAfee says they receive more than 300,000 samples of viruses and malwares a day; IT experts and officials attend the conference in Doha. PICTURES: Joey Aguilar

By Joey Aguilar/Staff Reporter

Thousands of computer viruses and malwares pose a threat to financial institutions and companies across the Middle East, a senior executive of global computer security software company McAfee has said.

Christiaan Beek, director of Incident Response and Forensics (EMEA) for McAfee, told Gulf Times that they received more than 300,000 samples of various types of viruses a day. He called them Advanced Precision Threats (APTs), which targeted banks, government institutions and different company networks to steal data and information.

“We see a lot of things going on. Attackers are taking on government sites,” he said.

Beek was speaking on the sidelines of the IT Security Roadshow organised by International Data Corporation (IDC) at Grand Hyatt Doha yesterday.

The event brought together around 100 senior information technology (IT) security managers from various companies in Qatar, especially those involved in the banking and energy sectors.

“Malwares are like tool kits built to get access to companies. They are used more as a weapon now instead of being used for play, like students did before,” he said.

Malwares have been focusing on penetrating financial institutions to steal banking information. Some companies do not notice it because it has hidden screens and attackers can manipulate data.

Besides banks, Beek noted that attackers have started targeting petrochemical companies as well - the Middle East becoming one of the battlegrounds for “cyber warfare”. “Actually, everybody is a target.”

“But I say 98% of APTs are not that advanced and could be detected easily,” he said, citing measures on how to prevent hacking.

The McAfee official compared a malware or a virus to a burglar who walks around a house, knocking on the doors and seeing if windows are open to get inside. Once inside, it will go to the main room and steal valuables.

“It is the same with a company. They knock on several doors of servers and see how they can exploit. Once inside, they can jump to the network,” he explained.

Beek spoke about the availability of technology in several companies in the region - firewalls and Intrusion Prevention System - but said there was a need to put all these together and have some specialists analyse the situation and detect malwares faster.

With more than 15 years of experience in information security assessment, Beek believes that having an external company test one’s environment can help solve many problems.   

Reiterating the importance of security, he urged these institutions to invest in what he calls “penetration testing”.

“Sometimes we see equipment (which are under attack) screaming for months but nobody responds. That is because they did not understand what was going on. So, they really have to invest in these things,” he pointed out.

On securing personal computers, he advised people to invest a little in anti-virus “not because I am working for McAfee”. Second, it is always safer to buy original and licensed software/programmes than to download pirated copies.

For online banking, it is important to always run checks, especially while making balance transfers. “Attackers are able to inject webpages and transfer money under water, a huge amount of money, and you don’t notice it,” he explained.

Changing and creating “strong passwords” more often also prevents attackers from penetrating bank accounts.

“If you are in a hotel room, for example, you don’t know what is going on in a wire. These could be ‘sniffed’ - we call it ‘sniffing’ - and malware may have stolen your password. So, it is important to change your password,” he stressed.

To create a “very strong password”, he suggested using the titles of familiar and favourite songs while adding a few characters to it.

For securing data and files, he said back-up was important especially if transactions were electronically done.

He said many companies did back-ups but never tested the restoration procedure. “Something goes down and they want to restore it, but suddenly it doesn’t work and then you have a big problem,” said Beek, who established the Cyber Defence Centre in Dubai.

Asked about the impression many people had that anti-virus companies were the ones that created viruses, he said he faced this question every day.

Beek explained that companies that were serious about the business could not afford to get involved in such practices. “Doing something like that - creating your own virus and then bringing it to the market - will kill your business. Security is a matter of trust,” he said. “I would say it’s a hoax.”

To stress his point, he gave the example of a couple of companies in the Czech Republic and Hungary that created viruses. The moment it was detected, they were out of business and could not work in the security sector again.

Beek works with a team of forensic experts, assisting various companies in the UK, South Africa and Russia.

“As we are building database intelligence ‘underground’, we can actually even assist in arresting the people behind it,” he said.

Meanwhile, IDC senior research director for software Ranjit Rajan pointed out that the increasing number of devices, applications and networks - such as Cloud, mobile phones and the social media - had given rise to new threats.

 

 

 

 

April 23, 2013 | 11:47 PM