Thursday, January 15, 2015

Last Year's Cyberattacks; Something Must Be Done!

Last year in September, Home Depot confirmed that the company had been attacked by hackers since April. As a result, 56 million Home Depot accounts were put at risk. The company anticpated to pay $62 million to fit the bill of the attack. Of those expenses are: legal fees, overtime compensation for staff, causing an estimated $90 million in costs for banks to replace 7.4 million debt and credit cards. Staff within Home Depot, who chose to remain anonymous, stated that the company’s information security department struggled with old software and high turnover. Home Depot resisted using the Endpoint security feature of Symantec’s cybersecurity program; which is a feature that tracks and alerts system administrators of suspicious activity. The company refused to use this security feature even though security specialists suggested that they did so. More appalling, the company did not encrypt customer card data until September 2014. Of course, we are not going to prevent every attack; cyberattacks are inevitable. However, there is no excuse why a large companies like Home Depot did not take the necessary steps to protect themselves. A company has much at stake and they at least owe it to their customers, if no one else to provide adequte protection. Now, customers might think twice about purchasing from Home Depot as a result of improper preparation. It would have been one thing if the proper steps of security were taken ahead of time but it is inexcusable not to take the proper precautions. Preparation is essential in securing our Homeland, without preparation we can expect an early demise. Home Depot was not the only company attacked, however, Target, J.P. Morgan, Staples, Healthcare.gov, Neiman Marcus and many others also suffered cyberattacks that left customers susceptible. 

Written by Bria White, a Homeland Security Graduate Assistant for the University of the District of Columbia.

Wednesday, January 14, 2015

Be prepared: What to do if an asteroid is heading our way

I am interested in what the dialogue will be about preparing for such an unexpected, massive catastrophe like this. It is certainly not an easy task, but being prepared for something like this is essential. This article speaks to preparedness, action, and reaction; which is the framework of Homeland Security.

 

Planetary security Be prepared: What to do if an asteroid is heading our way

Published 19 December 2014
Last month, experts from European Space Agency’s (ESA) Space Situational Awareness (SSA) program and Europe’s national disaster response organizations met for a two-day exercise on what to do if an asteroid is ever found to be heading our way. The exercise considered the threat from an imaginary, but plausible, asteroid, initially thought to range in size from twelve meters to thirty-eight meters — spanning roughly the range between the 2013 Chelyabinsk airburst and the 1908 Tunguska event — and travelling at 12.5 km/s. Teams were challenged to decide what should happen at five critical points in time, focused on 30, 26, 5, and 3 days before and one hour after impact.
Asteroid Eros // Source: commons.wikimedia.org
The European Space Agency (ESA) and national disaster response offices recently rehearsed how to react if a threatening space rock is ever discovered to be on a collision course with Earth.
Last month, experts from ESA’s Space Situational Awareness (SSA) program and Europe’s national disaster response organizations met for a two-day exercise on what to do if an asteroid is ever found to be heading our way.
In ESA’s first-ever asteroid impact exercise, they went through a countdown to an impact, practicing steps to be taken if near-Earth objects, or NEOs, of various sizes were detected.
An ESA release reports that the exercise considered the threat from an imaginary, but plausible, asteroid, initially thought to range in size from twelve m to thirty-eight meters — spanning roughly the range between the 2013 Chelyabinsk airburst and the 1908 Tunguska event — and travelling at 12.5 km/s.
Critical times to take action
Teams were challenged to decide what should happen at five critical points in time, focused on 30, 26, 5, and 3 days before and one hour after impact.
“There are a large number of variables to consider in predicting the effects and damage from any asteroid impact, making simulations such as these very complex,” says Detlef Koschny, head of NEO activities in the SSA office.
“These include the size, mass, speed, composition and impact angle. Nonetheless, this shouldn’t stop Europe from developing a comprehensive set of measures that could be taken by national civil authorities, which can be general enough to accommodate a range of possible effects.
“The first step is to study NEOs and their impact effects and understand the basic science.”
How should Europe react
Participants came from various departments and agencies of the ESA member states Germany and Switzerland, including Germany’s Federal Office of Civil Protection and Disaster Assistance. They studied questions such as: how should Europe react, who would need to know, which information would need to be distributed, and to whom?
“For example, within about three days before a predicted impact, we’d likely have relatively good estimates of the mass, size, composition and impact location,” says Gerhard Drolshagen of ESA’s NEO team.
“All of these directly affect the type of impact effects, amount of energy to be generated and hence potential reactions that civil authorities could take.”
Chelyabinsk: Injuries due to overpressure
During the 2013 Chelyabinsk event, for instance, the asteroid, with a mass of about 12,000 tons and a size of nineteen meters, hit the upper atmosphere at a shallow angle and a speed of about 18.6 km/s, exploding with the energy of 480 kilotons of TNT at an altitude of 25-30 km.
While potentially a real hazard, no injuries due to falling fragments were reported. Instead, more than 1,500 people were injured and 7,300 buildings damaged by the intense overpressure generated by the shockwave at Earth’s surface.
Many people were injured by shards of flying glass as they peered out of windows to see what was happening.
“In such a case, an appropriate warning by civil authorities would include simply telling people to stay away from windows, and remain within the strongest portions of a building, such as the cellar, similar to standard practice during tornados in the United States,” says Gerhard.
In a real strike, ESA’s role would be crucial. It will have to warn both civil protection authorities and decision-makers about the impact location and time. It would also have to share reliable scientific data, including possible impact effects, and provide trustworthy and authoritative information.
Establishing internationally coordinated procedures
The exercise ended on 25 November, a significant step forward at highlighting the unique factors in emergency planning for asteroid strikes, and possible courses of action. It also clarified a number of open points, including requirements from civil protection agencies and the type and time sequence of information that can be provided by ESA’s SSA.
It is another step in the continuing effort to set up an internationally coordinated procedure for information distribution and potential mitigation actions in case of an imminent threat.
The release notes that ESA’s NEO team is also working with international partners, agencies and organizations, including the UN, to help coordinate a global response to any future impact threat (see “Getting ready for asteroids”).
With the aim of strengthening ESA’s and Europe’s response, similar exercises will be held in the future. The next, in 2015, will include representatives from additional countries.

The science of airport bomb detection: chromatography

DetectionThe science of airport bomb detection: chromatography

By Martin Boland
Published 12 December 2014
As the holidays draw near, many of us will hop on a plane to visit friends and family — or just get away from it all. Some will be subjected to a swab at the airport to test clothes and baggage for explosives. So how does this process work? The answer is chromatography — a branch of separation chemistry — along with mass spectrometry. Although instrumental chromatography is a mature technology (the first instruments were produced just after WWII), new applications frequently pop up. Some are a matter of scale. Pharmaceutical companies that produce monoclonal antibodies (often used in cancer treatments) make use of capture chromatography to purify their products. On an industrial scale these can be tens of centimeters in diameter and meters in length (typical lab scale systems are a few millimeters diameter and 5-30cm long). Other uses can either be in a specific new application, such as detecting cocaine on bank notes using the gas chromatography systems often seen at airports as bomb and drug detectors.

As the holidays draw near, many of us will hop on a plane to visit friends and family — or just get away from it all. Some will be subjected to a swab at the airport to test clothes and baggage for explosives. So how does this process work?
The answer is chromatography — a branch of separation chemistry — along with mass spectrometry (which I will address in a later article).
The word “chromatography” is roughly translated from Greek as “the science of colors.” The reason for the name becomes obvious when you realize that most people have accidentally performed a simple chromatography experiment.
If you’ve ever spilled water onto a hand-written shopping list, then held it up to let the water run-off, you’ve probably noticed the ink diffuses across the paper, and that the pen’s color is made up from several pigments (if you’ve not, you can do the experiment — try it with a couple of pens of different brands, but the same color). This separation is chromatography.
There are several different types of chromatographic separation. What they all have in common is that a mixture of materials that need to be separated (the analytes) is washed over a solid material (called the matrix), causing the analytes to separate.
That may sound like chromatography is just filtration, or separation by particle size. In some cases, that is almost exactly what happens (size exclusion chromatography is often referred to as gel filtration chromatography).
But most chromatography methods work by some other chemical effect than just the size of the materials being separated, including (but not limited to):
  • normal-phase chromatography, such as ink on paper
  • reverse-phase chromatography, often used in university lab experiments
  • gas chromatography, seen in airport bomb detectors
  • capture” chromatography, used to purify drugs.
Each of these can be performed with one solvent, such as dropping water on your shopping list – known as isocratic (Greek for “equal power”) or with a changing mixture of solvents (known as a gradient).
So how does it work?
Technically speaking, it is the differential affinity of the analyte for the solvent and the solid matrix that drives chromatographic separation. So what does that mean, really?
You’ll need to bear with me here.
Have you ever been shopping with someone who stops to look at things while you’re trying to move though the store as quickly as possible?

Nuclear facilities Studying cancer risks near nuclear facilities

Nuclear facilities Studying cancer risks near nuclear facilities

Published 6 January 2015
The National Academy of Sciences has issues a brief report which provides an expert committee’s advice about general methodological considerations for carrying out a pilot study of cancer risks near seven nuclear facilities in the United States. The pilot study will assess the feasibility of two approaches that could be used in a nationwide study to analyze cancer risk near nuclear facilities regulated by the U.S. Nuclear Regulatory Commission (NRC).

Analysis of Cancer Risks in Populations Near Nuclear Facilities: Phase 2 Pilot Planning is a brief report from the National Academy of Sciences that provides an expert committee’s advice about general methodological considerations for carrying out a pilot study of cancer risks near seven nuclear facilities in the United States. The pilot study will assess the feasibility of two approaches that could be used in a nationwide study to analyze cancer risk near nuclear facilities regulated by the U.S. Nuclear Regulatory Commission (NRC).

A NAS release notes that the report comprises the committee’s advice, which is presented in the form of fourteen considerations related to procedures and methodologies for carrying out the pilot study; it is not intended to be a comprehensive workplan of how to conduct the pilot study. Among the considerations is an emphasis on transparency during the pilot study with respect to process, procedures, assumptions, and uncertainties about available information — as well as an emphasis on ongoing, two-way communication with stakeholders and the public.
One of the approaches that could be used in the pilot study is a population-level, or ecologic, study that would describe the rates of cancer occurrence and death in populations that live within approximately thirty miles of nuclear facilities. The ecologic study would examine multiple cancer types at all ages. A second approach is a case-control study, which would assess whether children younger than fifteen years old born near a nuclear facility are at a higher risk of developing cancer than those born farther away but still within a 30-mile radius of the facilities.
The pilot study will make use of existing health information from state cancer registries and vital statistics offices along with data from the nuclear facilities on radioactive effluent releases. The committee that wrote the report cautions that because of the small sample size, data collected during the pilot study will have limited use for estimating cancer risks in populations near the seven pilot nuclear facilities. Interpretation and communication of risk estimates from the pilot study, if reported, should be done with great caution. Carrying out the pilot study, which was recommended in a 2012 National Academy of Sciences report, is subject to receipt of funding from the sponsor, the U.S. Nuclear Regulatory Commission.
— Read more in Analysis of Cancer Risks in Populations Near Nuclear Facilities: Phase 2 Pilot Planning (National Academies Press, 2014)

New technology quickly traces source of tainted food

 

Food safety New technology quickly traces source of tainted food

Published 8 January 2015
 

Foodborne illnesses kill roughly 3,000 Americans each year and about 1 in 6 are sickened, according to the Centers for Disease Control and Prevention.
Yet most contaminated foods are never traced back to their source. This is because existing methods to track tainted food following its supply chain from table to farm are highly inefficient, jeopardizing the health of millions and costing the food industry billions. A typical process to trace food includes interviewing consumers and suppliers and examining every detail of the supply chain, a tedious method that takes weeks at best to complete.
Lawrence Livermore National Laboratory (LLNL) researchers, in collaboration with the startup DNATrek, have developed a cost-effective and highly efficient method to accurately trace contaminated food back to its source. Lawrence Livermore originally designed the technology, known as DNATrax, to safely track indoor and outdoor airflow patterns.
“One of the unexpected capabilities from DNATrax was being able to apply it to food products,” said George Farquar, an LLNL physical chemist who led a team of researchers that developed the technology for biosecurity applications. “You can spray it on food products in the field to identify and track the source of the food.”
An LLNL release reports that DNATrax are particles comprised of sugar and non-living and non-viable DNA that can serve as an invisible barcode. It’s an odorless and tasteless substance that’s been approved by the Food and Drug Administration as a food additive, safe for consumption. Think of it as a microscopic barcode that’s sprayed on food at the farm or processing plant.
If the food turns out to be contaminated when it reaches the store or dinner table, DNATrax can be lifted off the food and analyzed in the lab using polymerase chain reaction (PCR) to identify the source in an hour. A tainted apple, for example, can be traced back to the orchards by DNATrax to determine when it was picked, who picked it and potentially which tree it came from.
“We all hear horror stories about contaminated foods,” said DNATrek CEO Anthony Zografos, who recently licensed the technology from Lawrence Livermore. “We are not prepared to deal with an outbreak of pathogens such as E. coli and salmonella in tainted foods. However, DNATrax is a quick and efficient way to stop these foods from sickening more people and costing producers more money due to massive recalls triggered by poor traceability.”
About 128,000 Americans are hospitalized each year from contaminated foods, according to CDC statistics. Beyond health concerns, foodborne illnesses cost the food industry nearly $70 billion annually in the form of recalls and other related costs, according to the FDA.
DNATrax also can be used to trace fraudulent food back to producers using similar methods. Mislabeled foods are becoming a serious problem that are costing the food industry billions of dollars, Zografos said. It’s particularly problematic with premium goods such as olive oil and wine.
“Usually, the producers themselves are not the ones who commit the fraud,” Zografos said. “It’s committed down the supply chain.”
In the case of olive oil, DNATrax can be added to the olives as they are pressed into oil. If the fraudulent bottle is pulled off a store’s shelf, a quantitative analysis can be done on the DNATrax to determine how much of the oil has been diluted.
DNATrax’s original application was to monitor airflow patterns inside buildings and other facilities to plan safe evacuation routes and outside to determine routes that biological agents travel. The technology does not detect for biological agents, but is used in advance to ensure detection systems work properly.
To do this, tiny DNATrax particles are released as an aerosol and carried by the airflow inside a building. The particles are collected from the interior or exterior by swipes or filters, in a manner similar to forensic investigations. Using a PCR Thermo Cycler, a common instrument that serves as a photocopier for DNA, the data are analyzed to provide valuable information that can be used to improve the ability to protect lives if a harmful biological agent is released intentionally or accidentally.
“This technology provides a safe and cost-effective way to ensure biodetection systems are working as designed,” Farquar said. “So far, we’ve successfully conducted three tests at the Pentagon. Each test provided valuable information on how to enhance the Pentagon’s biodetection systems.”
In the future, Farquar hopes DNATrax can be used to assist in training to determine if personal protective equipment (PPE) — such as hazmat suits used by emergency responders and health care workers to treat Ebola patients — have been breached. The DNA particles can be applied to the PPE’s exterior, and if contaminants appear on a person’s skin, then a breach has occurred.
“This is important because current detection methods give a false impression of PPEs working properly,” Farquar said.

When the camera lies: our surveillance society needs a dose of integrity to be reliable


We all have rights, that is without a doubt but the real question is: When should the government draw the line on watching its citizens? Sure, cameras are there to keep us safe and to ensure that nothing illegal goes on, I get that. But it seems the governement is taking omnipresence to another level (being present in all places at all times). But when is enough, enough? When  does hiding cameras inside domes of wine-dark opacity infinge upon our right to privacy? The answer is unclear, however, I believe that we should have the right to know that we are being watched. Even if crime were to decrease, it would be a smoking gun because it would be very hard to argue that the fact that crime rates went down as a result of these camera's shrouded in secrecy. The article also poses a magnificent question and that is: Who is watching these camera's and ensuring the data they collect as evidence against us is reliable? We need to know these things because, "surveillance evidence is frequently being used in legal proceedings, however, the surveillants – law enforcement, shop-keepers with a camera in their shops, people with smartphones, etc. — have control over their recordings, and if these are the only ones, the one-sided curation of the evidence undermines their integrity".

Written by Bria White, a Homeland Security Graduate Assistant for the University of the District of Columbia.



http://www.homelandsecuritynewswire.com/dr20150113-when-the-camera-lies-our-surveillance-society-needs-a-dose-of-integrity-to-be-reliable?page=0,1

Source of article: Author Joshua Gans; Professor of Strategic Management at University of Toronto; Steve Mann is Professor of Electrical and Computer Engineering at University of Toronto. This story is published courtesy of  The Conversation (under Creative Commons-Attribution/No derivatives).










Can a hacker stop your car or your heart? Security and the Internet of Things


Our life is so consumed by technology that we may not even know all of the debilitating effects that could come of our cyberspace being attacked. Even something as innocent as you electronic car door locks could be compromised. Just think about it, we never really stop to think how heavily controlled our vehicles are on technology. Many of a vehicle’s fundamental elements– including the engine and brake control modules – are now electronically controlled. Researchers at the University of Washington were able to hack into and essentially control a highly computerized vehicle. Shockingly, the privacy of the inhabitants of the vehicle were compormised by listening in on their conversations; seeing as vehicles now have a feature where you can make phone calls from the car system. What is most frightening however, is the researchers were able to disable brake and lighting systems and brought the car to a complete stop on a simulated major highway. The group systematically and completely overtook control of the vehicle. Cybersecurity is needed now, more than ever in this ever-increasing digital age. Of course, technology has its strong suits, but the security and privacy implications or lack thereof, should not be ignored. There needs to be a concerted effort to improve security of future devices. Without increased security, the effects would be daunting! So let's all make a concerted effort to do what we can to secure our cyberspace; even if that means simply educating others.

Written by Bria White, a Homeland Security Graduate Assistant for the University of the District of Columbia.

http://www.homelandsecuritynewswire.com/dr20141215-can-a-hacker-stop-your-car-or-your-heart-security-and-the-internet-of-things?page=0,0

Source of Article: Temitope Oluwafemi is Ph.D. Student in Electrical Engineering at University of Washington. This story is published courtesy of  The Conversation (under Creative Commons-Attribution/No derivatives).