Showing posts with label cybersecurity. Show all posts
Showing posts with label cybersecurity. Show all posts

Protecting your data as you travel

Our last post on cybersecurity at the airport and on board some aircraft that offer on board connectivity dealt with rogue Wi-Fi hotspots and the measures you can take to protect your laptop from hackers. This post will deal with a bigger problem of information security throughout your travel itinerary and how you can protect yourself from data loss or even data theft during your travel.

Wi-Fi access points still play a major role as they are the entry points to your data that hackers, cybercriminals and the individuals involved in cyber espionage. The other option is when your laptop is stolen. So these miscreants have two gateways to your information. Free Wi-Fi is the most important amenity amongst Business Travelers, according to a survey done by American Airlines and HP in 2009. In fact business travelers responded that Wi-Fi was the "most important airport amenity, outscoring basic travels needs such as food by nearly 30 percentage points."

Information security and travel: Travelers needs to place more efforts in safeguarding their data.
For many of these travelers, the convenience of accessing free Wi-Fi at the airport lounge outweighs the risks of hacking and information theft. But this depends on the position in the pecking order. The loss of information by a high flying executive or government agent is definitely quite expensive!

Even for an "ordinary" business traveler, there are risks associated with malware installed via rogue Wi-Fi access points that might cost you lots of data and hundreds of dollars to restore your data and  remove the malware.

According to a study conducted by the Ponemon Institut, the physical loss of devices, and the accompanying combination of replacement cost, detection, forensics, data breach, lost intellectual property costs, lost productivity, and legal, consulting and regulatory expenses sets a company back an average of $49,246 per lost laptop! Lost laptops with encryptionhttp://www.blogger.com/post-edit.g?blogID=4596185367102352450&postID=4789261814681384493 however cost companies only $20,000, which is 29,000 less than for an unencrypted laptop. Encrypted disks however safeguard data by scrambling information on them. They unlock that information only when the user enters the proper passcode.

Tips for Safeguarding your data during your travel
There are a few simple steps that you can take to ensure your data is safe during your travel. Travel can be a headache and who wants an extra head ace post travel? Use the following steps to safeguard your data and ensure a smooth and safe Wi-Fi access as you hop from one city to another in your business travels:
  • Use an encrypted disk to safeguard the information on your laptop or smart phone and make sure you log off of your computer when you're not using it.In most cases when you hibernate your computer, its memory is recorded unencrypted. You can also use a free software called TrueCript(http://www.truecrypt.org) that allows you to encrypt the content of your local drive and on USB Flash drives.
  • Turn off your wireless and Bluetooth connections if you're not using them. These are electronic gateways into your devices and as long as they are on, hackers can scan for open Wi-Fi peer to peer connections and gain access to your files. Hackers can use software like Aerodump to quickly figure out the existing wireless access points. Woo unto you if yours is one of them and you are not well armed to fend off attacks.
  • Use an anti-glare shield on your computer to prevent others from spying on your screen. With such shields, you must be face-to-face with the screen to be able to read it. 
  •  Regularly back up the data on your laptop or smart phone. Several companies offer backup services, but you can also save information on other computers and disks. Even if your data is encrypted- eliminating your fear of sensitive information getting stolen -backing up the data will make it easy to transfer to a new phone or laptop.
  •  If you lose your smart phone and don't want others to access your information, call your provider and request that the device be wiped of information. There also exist security software that allows you to send a text message to your phone that will remotely wipe it and block others from accessing its content. 
  •  To ensure that you're visiting an authentic Web site and not getting duped by a phishing scheme, some experts suggest logging onto those sites through your company's VPN connection.
  • Be vigilant to avoid losing or forgetting your laptop at the lounge. Avoid sleeping or taking a nap with the laptop on your lap; place the laptop on your lap instead of a table when using it as it's much easier to forget the laptop on the table but impossible to forget to carry it with you when it's on your lap :)

Email Us at FlightAfricablog@gmail.com

The dangers of rogue Wi-Fi Hotspots in Airports

Just when you thought your troubles were over after long immigration queues, a delayed flight, cancelled flights, congestion, long immigration queues,extra baggage fees, intrusive security screening there is just one more problem you might endure before you finally board your flight, rogue Wi-Fi access points in airport lounges!

Many travelers are only too happy to settle at the lounge for a few moments online to do some business, write  a few reports, reply to a few emails before a long flight and update friends and family via social media before boarding flight. Sometimes, delayed flights might force travelers to wait for hours in an airport lounge. To easen the burden and anxiety on travelers, many airports have installed free Wi-Fi hotspots on airport lounges to enable travelers to get online before boarding the aircraft.

Free Wi-Fi at the airport comes with the dangers of rogue Wi-Fi access points
What you might not know is that hackers and cybercriminals might also be sitting in the same lounge, masquerading as free public Wi-Fi providers to gain access to travelers laptops and steal private information, read your emails, your bank account details, reports and more private information.

These fake Wi-Fi hotspots are called "rogue Wi-Fi" as it's not the official Wi-Fi provided by the airport but an illegal local network set up to infiltrate your information. It's very difficult for a traveler to differentiate between a good internet access point and a rogue network.

The traveler's laptop will simply provide list of Wi-Fi spots available and the traveler will randomly connect to one of the available options, especially if it has a 'familiar' name like "Airport Wi-Fi" or "free Airport-Wi-Fi". It's virtually impossible for the traveler to determine which is which and therein lies the loophole that hackers and cybercriminals exploit.

Many airport security are not trained in monitoring rogue Wi-Fi Access Points in the airport and are in many cases more concerned with the more important task of ensuring physical security at the airport to prevent the next underwear bomber from slipping past the airport security system.

This gives the hackers a free ride in the airport. They might just be your regular guy using their laptop while in the real sense, they are actually setting up a rogue Wi-Fi access point.

As a traveler, it's safe to connect to Facebook, Twitter or other social networks but exercise great caution when performing online transactions which will require you to enter your credit card information! One sure way to exercise caution is ascertain the true identity of the legitimate airport Wi-Fi by for example asking around and connecting to only those networks whose identities you trust. Make sure that your communication is secure, disconnect the wireless when you stop using it, and maintain the list of wireless connections that you use on your laptop so that you don't accidentally connect to networks that may spring up when you're traveling.

Email Us at FlightAfricablog@gmail.com

Safety and Travel: CyberSecurity Tips for Travelers

Safe travel begins at the point where you are booking the ticket for your next flight. Credit card fraud is increasingly becoming a major issue in travel with airlines and travelers losing billions of dollars every year. This is becoming more apparent as more travelers are now opting to purchasing their tickets online through airline booking engines, online travel agencies, affiliate websites and more. The distribution infrastructure for airline tickets has broadened and so have the cyber threats. Devices such smartphones and e-passports have also increased security risks for travelers. If you are the techie traveler, here are a few tips to keep safe online before you board your next flight:

Some deals are literally too good to be true:
Airlines and travel retailers are literally bombarding travelers with deals, particularly during the peak travel seasons like Easter Holidays, Christmas, New Year, August Holidays etc. These deals can be sold via an airline's website, partner websites, affiliate websites and other online distribution infrastructure. With so many channels, it can be difficult for naive bargain hunters to distinguish trusted websites from online scams. Cyber criminals always take advantage of such to dupe customers into buying into non existent deals. Always reaserch, thoroughly, a company behind the latest "hot" travel or holiday offers before committing your cash. Buy from trusted travel providers. The safest place to buy a ticket is from an airline website's booking engine.

Groupon Spoofing:  
Cybercriminals are capable of spoofing popular online group buying websites and install malicious software on your computer to steal your financial information and money. What initially looks like an awesome travel deal to South Africa on "Expedia" or "Groupon" eventually turns out to be an elaborate scam that costs you thousands of dollars in a matter of minutes. These scammers build fake websites with the familiar feel and look of your normal online travel website be it Expedia, Groupon, Kulula Daddy's Deals, Travelstart, Priceline or eDreams. In some cases, they might even spoof airline websites although this is quite rare. The idea is make consumers who are less diligent trust these fake websites as the real thing. They are normally accompanied by highly discounted travel offers. The trick to escaping scams online is to research and research well. Don't trust unsolicited emails, if you are looking for a great travel product, then use search tools and buy from the trusted service providers.

Pay for your trips with Credit Cards
Always pay for your trips using a credit card. For Africans, this might be a challenge as many African countries are now facing wholesale blacklisting or greylisting of credit cards from their countries by international service providers due to perceived threat levels supposedly posed by the credit card transactions from many African nations. Many international providers are no longer honoring transactions by credit cards issued in the African digital space. Credit cards normally protect users against losses due to theft and fraud.

Safety in the public: booking your travel in a cybercafe? Think again
The easiest way for cybercriminals to steal your login credentials and financial information is via public browsing arenas such as cybercafes, libraries, airports or hotels. Never use a shared machine for online transactions, you are placing yourself at a significant risk by doing so. In Kenya and many parts of Africa, this might not be practical due to the low rate of internet access and broadband subscription so many users are likely to be forced to share computers in public places such as cybercafes. Take some extra precautions, always enable private browsing when using a shared machine in a cybercafe, hotel, conference etc. Clear all browsing history, cookies, cache and temp files after every internet session; never expose your debit card/credit card number, cybercafes are quite congested and it's very easy or someone to spy on your card information, never "Remember Password", never download files in public computers, you are likely to forget to delete them, leaving your private info or everyone to see; empty the Recycle Bin for all the files you have used and deleted during a login session. In some cases, the public computers could be installed with spyware such as Keylogger software that reads and stores every information you type into the keyboard. Finally advice, never visit websites that require you to login or enter credit card info in public computers.

The dangers of public Wi-Fi
Avoid using public Wi-Fi as much as possible even if it's provided freely at the airport, the plane or hotel. Cybercriminals can set up rogue Wi-Fi access points tat once you connect into, will ive them access to all your information. It's difficult for many travelers to tell the rogue Wi-Fi from the legitimate Wi-Fi. Ask the airline for the name of the Wi-Fi network where you are not sure. Also, instead of public Wi-Fi, use Mi-Fi instead(MiFi Mobile Hotspots) or tether your laptop, notebook or tablet to your smartphone's 3G service.

Precautions with your e-Passports
In the US, all passports issued since 2007 are e-Passports. In Africa, passports are still as they once were. A dark blue booklet with several leaflets. If you are using an e-Passport, ten there are safety precautions that you must take before you embark on your journey to the airport immigration queue. e-Passports contain an electronic chip with biometric data. The RFID chip containing your biometric details can easily be wirelessly read by criminals and identity thieves from hundreds of feet away, perhaps standing in the same queue as you! A good precaution for protecting the integrity of the information on your e-Passport is buying an RFID blocking passport wallet to keep your information safe.

Bluetooth threats during your travel
Turn off Bluetooth on your mobile devices when not in use. Hackers can use bluetooth to access your system and steal private information. Hackers can also install Malicious software to your system via Bluetooth
Also be aware that Bluetooth headsets can be eavesdropped on, allowing criminals to easily record your conversations.

Careful use of social media when traveling
Announcing to everyone via social media that you are traveling makes you a very easy target. Some travelers go as far as tweeting their Flight number, the city they are traveling to and the hotel you will be staying in thus creating a digital trail for criminals in your destination city to easily locate your whereabouts and target you. Watch the amount of formation that you divulge online. KLM recently introduced a Meet and Seat program that allows travelers to share certain information from their social media profiles after booking a flight in order to help them in choosing a preferred seat mate during a  flight. While this is an interesting innovation, it can be abused in many ways by criminals and stalkers.


Email Us at FlightAfricablog@gmail.com

Airlines Grappling with Cybersecurity Threats

Electronic data exchange is becoming a huge part of airline operations as many airlines shift transactions online to cut on costs. Many airlines are also launching online eCommerce website wheres travelers can purchase anything from frequent flyer miles to luxury items, hotel bookings, car bookings and exclusive tour offers in exotic resorts and many more.

But lurking behind these innovative business models and services is the shadow of cyberthreats and online credit card fraud.
Cybersecurity: Airlines lost $1.4 billion in 2010 to online credit card fraud
According to the 2010 Deloitte Airline Fraud Report, the scale of credit card fraud increased rapidly in the years between 2006 and 2009, driven largely by the tremendous growth in online bookings. Today's traveler is likely to book their ticket on online travel agencies like Expedia, Priceline, Orbitz, Travelstart or on airline websites' booking engines. Given that many users are purchasing tickets online for the first time or are not well attuned to the existing cyberthreats and online fraud, cybercriminals are shoving their way into the online booking business to take advantage of naive customers and lax airline online security systems.

On average, an airline loses a whopping $2.4 million per year to fraud.  Almost half of the airlines surveyed said that fraud associated with e-commerce and the Internet had increased between 2008 and 2009. Some 35% noted an increase in card fraud associated with point of sale or handheld devices, and 22% noted an increase in the number of attempts to breach IT security and firewalls.

Today's traveler and travel is never complete without sophisticated devices such smartphones, iPads, laptops, netbooks and bluetooth enabled devices which make our travel experience lot more bearable. Sadly these are also the softest targets for cybercriminals who may attack from airport lounges; attacks include identity theft, rogue Wi-Fi hotspots to new wirelessly-accessible e-passports. Some airports provide free Wi-Fi services but it's extremely difficult for a traveler to tell the difference of free Wi-Fi from a rogue free, set up to steal client information.

As more African travelers take to the skies, African banks must install extra layers of security authentication in the debit cards and credit cards beyond the information displayed on the card which is normally sufficient for a transaction.

How airlines lose money to cybercriminals
Airlines lose money to cybercriminals mainly through hacking incidents and attempts to breach its security walls.  Hacking groups and networks can compromise an airline's information security wall and in the process steal sensitive credit card information from the airline and its customers. Negative perceptions on the security of an airline's website and the subsequent loss of trust in the airline's security systems can also drive customers to book their flights with more trusted agents such as online travel agencies thus adding extra expenses to the airline and loss of business and also exposing the travelers to even greater online threats. Recently the website of the Israeli airline was disrupted by a Saudi hacking network although in this case, no sensitive financial or flight information was stolen from the airline but the airline was forced to take its website down as a result of the attack thus disrupting its online operations.

Although credit card fraud is regarded as a serious risk by most airlines, the Deloitte Report found that only about 50% of the airlines had a formal system in place to track this fraud.

The weakness is being addressed, however. The new 2011 Cybersource Airline Fraud Survey found that in 2010, airlines lost a total of $1.4 billion due to online credit card fraud perpetrated through their websites, representing 0.9% of total worldwide online ticket sales. But these figures were 31% better than the findings from the previous survey in 2008.

Airlines are doing everything they can to address the problem of credit card fraud, and to comply with the Payment Card Industry Data Security Standards (PCI-DSS), a security standard developed in 2006 by the major international payment schemes to provide protection to their cardholders. Any organization that processes, stores or transmits cardholder data is required to comply with these standards.

Low Cost Airlines at Greatest Risk of Credit Card Fraud
Further work on the issue will progress matters even more. In particular, there is a need to assist airlines that have less experience of online sales. These tend to suffer from the highest rates of fraud as a percentage of sales. Low-fare airlines have the lowest rates of fraud, probably because of their online savvy and increased awareness that every cent counts.

Credit card fraud: Countermeasures by IATA
IATA does not collect statistics on online fraud, but is active in this area. It has developed the Perseuss program, which offers a secure platform where airlines can legally share information about known fraudulent activity. The data can be matched with airline sales data, such as e-mail addresses or IP addresses, to identify suspect transactions. Perseuss is a subscription service, and more than 60 airlines are now involved to various degrees.

“Some airlines have recouped the annual cost of Perseuss in just a few months,” says Christophe Kato, IATA’s Project Manager for the Perseuss program. “We don’t offer this service to make a profit. The value is to the community of users, and what they can bring to the table through their meetings and new relationships.”
IATA has also developed its own PCI-DSS program, which secures and protects BSP sales via agencies. Whenever a credit card is used, airlines must ensure their systems are in line with PCI-DSS.

“IATA plays a significant role in trying to prevent cyber credit card crime,” says Kato. “Ensuring that PCI-DSS is correctly implemented means the risk can be passed from the airline to the merchant.”
Detecting fraud is another important area. Some airlines use automated systems to do this; others tend to do larger numbers of manual checks. “It is really a question of trying to spot anything that is suspicious,” says Kato. “It is not an exact science. Some airlines have in-house fraud analysts, while others outsource to specialist companies. Risk scores can be applied to each transaction, and those with the largest risk scores can then be given manual checks.”

The terrorist cyberthreats to airlines
Terrorists don't just blow up planes, they also perpetuate terror on the airlines through the internet. A case in point is the recent hacking of an Israeli airline website by a Saudi Group.

Greater cyberthreats with new generation of aircraft
Losing money is one thing; losing lives is something else again. Cyber terrorism poses especially serious challenges for airlines that will be taking delivery of the new generation of aircraft. In some cases, it may even require airlines to rethink the structure of their security and IT divisions.

The International Civil Aviation Organization (ICAO) has identified cyber terrorism as a distinct threat to the aviation industry that needs attention. On 17 November 2010, a new ICAO Recommended Practice related to cyber threats was adopted and became applicable on 1 July 2011. It suggests that each ICAO Contracting State should develop measures to protect information and communication technology systems used for civil aviation purposes from interference that could jeopardize the safety of civil aviation. Vulnerability assessments relating to cyber security are recommended, with the objective of evaluating the efficiency of mitigation measures and identifying vulnerabilities from a threat-based perspective.

Chamindra Lenawa of Air Astana says the airline has a resilient system with several layers of defense. “Our main servers are at our operational hub in Almaty, but we have the core operational structure replicated on an offline copy in Astana,” Lenawa notes. “As for the data itself, we also have hot‑standby systems, which replicate the data of critical systems in the form of regular snapshots so that if for any reason the data becomes corrupted, we have standby systems that can be activated quickly.”

Cyber terrorism’s increasing threat to airlines has been enhanced by globalization and the ubiquity of the Internet. An attack on an airline’s IT systems can be regarded as cyber terrorism if it brings down or paralyzes any critical system. But this can extend to the more frightening possibility that it could actually cause damage to an aircraft.

“Many future efficiency gains will be based on network connectivity and electronic data exchange,” says Ken Dunlap, IATA’s Director of Security. “The new generation of aircraft will be much more interactive in terms of automated electronic data exchange than the present generation of aircraft. These new aircraft are being discussed as ‘all-electric’ models. It is not only the primary fly-by-wire flight controls; they will have a whole range of systems operating electronically, and data will be updated automatically in real time, rather than the static updating that takes place today.”

Ensuring that this data is transferred between the ground and aircraft securely is the challenge airlines must address. It is essential that all stakeholders in the civil aviation industry work together to ensure there are no glitches.

The movies come to life
“This is a relatively new concern for airlines,” says Pascal Andrei, Director of Aircraft Security at Airbus. “Conventional security threats, such as bombs, disruptive passengers, smuggled baggage, and cargo are already being managed effectively, although these are constantly evolving. Now airlines must learn to manage cyber threats.”
Cybersecurity: With new generation aircraft and the threats of cyber terrorism, future terrorists may not need to blow themselves up to inflict terror in the aviation industry

In the film Die Hard 2, an aircraft’s systems were fooled by cyber hackers into thinking it was flying 200 feet higher than it actually was, through resetting the instrument landing system.

Andrei says this is no longer merely a fictional scenario. “It is not just a matter of ensuring that the channels of data transmission are secure, but also of ensuring that the information transmitted through those channels is correct. Aircraft have to rely on external data coming into the aircraft. If that information is not correct, it could jeopardize the safety of the flight.”

Manufacturers deliver aircraft with security features embedded, but once the aircraft has been delivered, it is the responsibility of the airline to maintain that level of security throughout the life of the aircraft.
“Airlines need to understand the threat evolution associated with new IT technologies,” says Andrei. “These new technologies can be taken hostage. Airlines need to know what they need to do to protect and maintain the level of security on the aircraft itself, which is the last line of defense.

“With more and more open systems and electronic connections between the various stakeholders in the air transport industry, the risks are increasing,” he adds. “All applications have potential bugs, and this, coupled with the interconnectivity between the aircraft and the ground, creates the challenge.”
Opening the doors

The aircraft manufacturers have already started a dialogue with airlines about these matters, but much more needs to be done to bring other stakeholders into the discussions. Airbus’s annual Aircraft Security Users Panel (ASUP) meetings have been running—strictly behind closed doors—for several years now, bringing together the heads of security at airlines with Airbus. This year, for the first time, Boeing was invited to attend the ASUP meeting, and Andrei says that next year Bombardier and Embraer will also be invited.

Boeing understands the importance of collaborative efforts and is itself part of industry groups, such as the US Department of Transportation’s Rapid Response Team. “We are working with everyone in the aviation industry to develop recommendations for common industry-wide security standards,” says Toby Bright, Boeing Commercial Airplanes Executive Vice President of Sales. “We have no competitors when it comes to safety and security, only colleagues.”

In October 2011, at the IATA AVSEC conference, a panel discussion highlighted the importance of bringing more stakeholders into these sorts of talk. “Airlines, OEMs, airport operators, and air navigation service providers all need to be fully aware of the challenge of providing accurate information within secure communication channels,” says IATA’s Dunlap.

“Five years ago, I was spending most of my time on the physical aspects of airline security,” he continues. “Now I am spending the majority of my time on technology and data exchange issues. Whether it involves airport or aircraft security, the focus now encompasses the integrity of the data stream in addition to the physical aspects of the systems.”

This new outlook is why airlines may need to rethink their security and IT divisions. The way forward will blend a diverse mix of skills.

Dunlap says that airlines must optimize their organizations to provide secure electronic communications, not only for ground‑based systems, but also for electronic data exchange between their ground systems, airport systems, air navigation systems, and their aircraft.

“Does this come under the responsibility of the IT division or the Security division?” he asks. “Airlines are already dealing with these questions today.”

The answers are vital to the future of the industry. 

Work can be republished with attribution. Email Us africadomainnames@gmail.com


Email Us at FlightAfricablog@gmail.com