Recent

Proof: SA Is First In Line For Emerging Advanced Attacks

May 21, 2018

Author: Alastair Waldeck, Head of Marketing (Snode)   In an article published by ITWeb last week, Nithen Naidoo (Snode Founder and CEO) stated that South Africa is often first in line for newly emerging, advanced attacks. Developing economies such as Bangladesh, Vietnam and South Africa are viewed as soft, and lucrative, targets by organised crime syndicates with highly advanced cyber capabilities due to the fact that they have not made the same kind of security investments as their developed nation counterparts. One of the interesting findings mentioned in the article was the increasing trend of Snode clients being affected by an old "commercial-grade" Trojan called FinSpy, which was widely reported in 2013. "The malware is not necessarily new but the attack vectors to deliver the malware are new and quite advanced. This is similar to the Terdot malware, which delivered the old Zeus Trojan.", stated Naidoo. At the same time we were detecting this type of activity within our SA client base, AlienVault’s Open Threat Exchange (OTX) reported the discovery of a new version of FinFisher, a malware that is currently evading notice and leveraging social media to threaten critics in Turkey and beyond. It is specifically coded in order to appear as simple criminal malware, however there are several forensic artefacts which provide a clear indication that the agent identified is in fact FinSpy. The most substantial change in this latest version when compared to the original FinSpy malware is the steps it has taken to address the failures that led to the original software’s discovery and acknowledgement by security researchers. FinSpy infects its targets by redirecting the user, when downloading an application, to a version of an application that is infected with the FinFisher malware. This then allows the attacker to perform several activities such as live surveillance through webcams and microphones, keylogging, and exfiltration of files. The fact that this trend of the new, emerging FinFisher malware was detected by the Snode Guardian Cybersecurity Platform at the same time as organisations abroad is proof that South Africa is indeed a prime target for new and advanced cyberattacks. The need for South African organisations to not only ensure that they have adequate security measures in place to detect, prevent and respond against these attacks but also to share their threat intelligence and disclose when and how they are being attacked, is now more crucial than ever. In this ever-changing technological landscape, organisations are forced to find new ways to increase their security posture and minimise their risk. The Snode Guardian cybersecurity platform utilises learning machines, mathematics, and a synergy between both human and artificial intelligence (Intelligence Amplification) to monitor, detect and proactively respond to all threats on every device within your network, from traditional network devices through to BYOD, cloud and IoT devices. Naidoo will be presenting at the upcoming ITWeb Security Summit, and delegates attending his talk will learn about the emerging threats we see in Snode's South African client environments, as well as the key issues affecting the majority of its South African clients. He will also discuss the defence strategies clients have used that best address these issues. The ITWeb Security Summit is southern Africa’s definitive conference and expo for information security, IT and business professionals. This year, over 70 expert speakers will deliver key insights across 7 tracks, including workshops and training courses during the expanded 5-day event. The ITWeb Security Summit will be staged at Vodacom World, Midrand, from 22 – 23 May 2018; and CTICC Cape Town on 29 May 2018. Focused and interactive workshops as well as in-depth training courses will be run in the days around the main conference and exhibition. For more information, go to www.securitysummit.co.za. For information on Security Summit Cape Town, click here.

Young Minds Prepare For #SS18 Hack

April 21, 2018

Author: Alastair Waldeck, Head of Marketing (Snode)   A group of motivated young men and women gathered in the offices of The Business Clinic in Johannesburg CBD early on Saturday morning for the 2nd Annual #SS18Hack Ideathon. The Ideathon provided these aspiring cybersecurity and IT professionals with an opportunity to meet and greet with some of the top minds in the industry as well as to learn a thing or two from the four main workshops presented on the day. The Ideathon serves as pre-selection event for the larger, main event; the #SS18 Hackathon which will be held at Vodaworld in Midrand on the 22-23 May. The day began with an introduction from Mr Lucky Litelu (Executive Chairman and CEO of ICRD GROUP) and the sponsorship team of Tiyani Ngonyama (COO, Geekulcha), Allyson Towle (Senior Conference Director, ITWeb Events) and Alastair Waldeck (Head of Marketing, Snode). Our first speaker of the day was Ridewaan Hanslo from the CSIR who gave the attendees a comprehensive overview of Web App Security by providing several examples of different types of attacks, attackers, interactive examples how to practically identify and prevent these attacks as well as how to ensure that your next application is created with security as a priority. Second up was our very own Founder and CEO, Nithen Naidoo. He provided an introduction to the AI and Infosec industry by discussing the latest tools and methods within the cybersecurity and data analytics industry as well as how to analyse vast quantities of data in real-time in order to pull various insights, detect anomalies and trends and to be able to predict and defend against ever-evolving cyberattacks. After a quick break where the guys were able to refuel, get to know one another, ask questions and discuss ideas with the presenters, sponsors and other attendees, we returned to our seats for the 3rd workshop of the day. Francois Mouton from the CSIR was up next. Francois gave us a presentation on Ethical Hacking with a focus on his speciality, social engineering. By providing us with some simple, everyday examples of how human’s inherent trust can be our own downfall, he made us realise how simple a cyberattack can really be and how our perception of a cybercriminal being a person in a hoodie hiding behind a laptop is far from the truth. Last, but certainly not least, Kimoon Kim from Siatik spoke us through the concepts of Big Data and Machine Learning. By focusing on powerful platforms that are readily available for us to use such as Google Cloud and BigQuery, the attendees discovered how to easily analyse all their data, regardless of size, in real-time. The rest of the day was spent brainstorming ideas, absorbing even more information and inspiration from the mentors and speakers, and coming up with ideas that will not only take them through to the next round in Midrand, but also to potentially win them top spot at the #SS18 Hackathon later next month! The top three teams with the ideas that showed most potential were: - Bro-Coders - CleverKleva - TechnoGeeks - A special mention went to team Nosey. We look forward to seeing everyone again in a month’s time and would like to thank all the sponsors and speakers for their involvement in making this event successful!   Sponsors for the event: Snode, ITWeb, Geekulcha, The Business Clinic, Northern Cape Department of Economic Development and Tourism.

Re-invented Zeus malware Terdot, defied explanation, but cannot defeat detection

December 6, 2017

Author: Nithen Naidoo, Founder and CEO (Snode)   During October 2017, Snode's cybersecurity platform (Guardian) found an increasing trend in SA networks being infected by the well-known Zeus malware. Although the Zeus Trojan (discovered back in July 2007) is still considered one of the most prolific malware variants affecting the Internet today; the retro plague perplexed our analysts. The finding’s fallacy is that most (if not all) traditional anti-malware controls today can reliably defend against the Zeus malware threat. At the time, we could not explain how a 10-year-old Trojan was (as reported by our learning machine) effortlessly propagating through large SA corporate networks; unhindered and undetected. A fitting explanation was later provided courtesy of the global security technology firm, Bitdefender. Bitdefender’s researchers released a paper (mid November 2017) on the discovery of a new “Zeus inspired” Trojan, called Terdot. A surprising insight from their research is that they first discovered the Trojan in October 2016; which highlights a challenge in our machine-assisted analytics. You see, the machine-learnt Zeus malware's "pattern of behaviour" was now mimicked by Terdot. As a matter of fact, Snode's learning machine could only learn to accurately identify Terdot, by unlearning everything it knew about the Zeus malware. Hence why our learning machine is augmented by our (human) analysts as it allowed us to reliably distinguish between these two malware variants. Now, it is not often that a cybersecurity vendor will openly discuss the flaws in their machine learning and pattern recognition software. However, at Snode we do not build software, we deliver solutions (and we value transparency). This is why our machine-assisted analytics is backed by (and never delivered without) our human intelligence. Something to keep in mind, if you believe that AI-supported threat detection (neural network based pattern recognition) software will transcend your security posture to a cybersecurity nirvana, it won't, at least not yet. However, by enhancing your posture with such technology (defence in depth), you wont get trapped in a false sense of security, solely relying on the latest antivirus signatures to save you. Keep in mind that Terdot, was circulating in the wild for an entire year without signature-based detection. I would like to thank and give credit to the Bitdefender Research Labs for making the Terdot discovery. For more information, you can find the full research paper here.

Why a well-designed HCI is critical to your AI driven cybersecurity solution

November 24, 2017

Author: Nithen Naidoo, Founder and CEO   Most readers of this post will know Deep Blue, the computer that beat chess champion Garry Kasparov in 1996. Since then, and more so recently, Artificial Intelligence (AI) has been an industry buzzword and “the Tao” of the future. I love everything about AI, but I believe in Intelligence Amplification (IA). IA is the synergy of human and machine (as opposed to the substitution), augmenting our capabilities (not replacing them). So, why do I think IA is better? Let’s begin with a lesser known story, about a lesser known chess competition. Eight years after Deep Blue, Kasparov competed in another chess competition which allowed humans to pair up with computers. Naturally, you would expect the best human-computer duo to dominate. Actually, amateur chess players with suboptimal computing platforms won. The upset was credited to a well-designed interface between a well-trained human and a data-rich computing platform. So, having a data-rich platform with effective AI capability is important – but meaningless, if you (the analyst) can’t rapidly navigate, correlate, contextualise and gain insight from your data. Hence, we developed Snode’s cybersecurity solution with - data fusion at scale and machine-assisted analytics. However, more importantly, we designed a frictionless Human-Computer-Interface (HCI) - prioritising, maximising and galvanising the synergy between human and machine.

Popular

#SS19Hack underway at Security Summit 2019

May 28, 2019

Author: ITWeb With the first day of ITWeb’s 2019 Security Summit underway at the Sandton Convention Centre in Johannesburg, 50 young tech enthusiasts are participating in this years’ Hackathon event sponsored by PwC. The hackathon, held by ITWeb in conjunction with ICT skills development company Geekulcha and Snode Technologies, aims to nurture individuals who are keen to develop their skills through learning and innovation, and who have a passion for cyber security.  Running for the third time alongside the summit, this year’s hackathon is themed ‘Protecting connected citizens in the 4IR’.  Aptly called #SS19hack, the hackathon has participants as young as 13 participating and engaging with industry leaders. Lerouro Mogeora, aged 13, is the youngest participant this year, while for 14-year old Sifiso Nkabinde this is the second year at the event. Those participating range from high school pupils to students from the Vaal University, the Tshwane University of Technology and the University of the Witwatersrand.  There are 13 teams hacking it out, creating secure IoT applications. As they code, they need to identify at least three vulnerabilities within their applications utilising OWASP, an open source cyber security platform for checking common vulnerabilities. OWASP also has tools to assist the coders in improving the security of their software. A week ago, at a similar hackathon event in Kimberly, eight teams were competing, with the winning team there creating a solution that provides encrypted file share and messaging applications for government ministries. The top three teams from the event will also have their projects judged alongside those in Johannesburg. The overall winning team from the two Hackathons will win R20 000 sponsored by Micro Focus, with the second and third placed teams winning R10 000 and R5 000 respectively, courtesy of MTN.  An added bonus for the top team in Johannesburg is that they will be awarded the Tshimologong Precinct Security Summit Hackathon trophy.  The #SS19hack continues during the second day of the ITWeb Security Summit 2019. Mentors Ivan Regasek, CEO, ITWebRidewaan Hanslo, CSIR Steve Jump, TelkomSolomon Bhala, PwCBernard Mashala, Transet Nithen Naidoo, SnodeFrancois Mouton, CyanreIcconies Ramatsakane, PwCGift Nyembe, PwCMarco Loots, PwCMichael van Rensburg, SnodeTsholofelo Rantao, PwCThulisile Dlamini, Ikusasa Tech Solutions  Panel of judges Doreen Mokoena, ZADNALucy Motsieloa, PwCSeth Robbertse, Micro FocusKendal Makgamathe, TshimologongSorene Assefa, Cyber Czar       

Freshworks Networking Meet – Consumerisation of IT

May 23, 2019

On Thursday 23 May 2019, we attended the Freshworks Networking Meet talking about the impact of an increasingly connected world. In 2019, the influence of IoT, cloud, and BYOD have a dramatic impact, not only in our personal lives, but also in the world of business. It is crucial that organisations shift their thinking from a historic view of cybersecurity as a “grudge purchase” to something that is vital to the running of your organisation, is crucial for success and can often win battles in the boardroom. Our Founder and CEO, Nithen Naidoo, spoke about the changes we have seen in our client environments, especially with the workforce becoming increasingly dominated by millennials who expect to be connected at all times. Unlike traditional antivirus software, DLPs and firewalls, the Guardian platform is able to detect even the smallest changes in your networked environment and provides organisations with an unprecedented level of visibility and control of their network. It allows businesses across the globe to identify and prevent potential data exfiltration, malware infections and avoid catastrophic ransomware attacks such as the well-known Wannacry malware. Once the floor was opened for questions, the audience raised concerns around how secure (1) Mac vs Windows Operating Systems are and (2) mobile vs desktop platforms, with a mention of the recent Huawei-Google ban. The long and short of it is that there is no one platform that is more or less secure than another, every system contains some form of vulnerability and can be exploited just as easily, the question comes in around what is most lucrative for the attacker. The myth of a Mac being more secure than a Windows PC is largely due to the fact that there are simply more Windows PCs out there and most organisations across the globe make use of Windows Operating Systems as the norm. Attackers, like businesses, often focus on ROI and will always focus their attention on where they believe they can have the greatest impact. When it comes to the mobile industry, mobile malware is growing at a rapid rate and often mobile devices are a greater concern than laptop or desktop devices as many users often blindly accept permissions on all their applications and are generally more trusting when it comes to a potentially “life-changing” application that appears on the app store. This poses a particular risk to organisations as these devices are often brought into the office and are connecting to the corporate network, allowing the malware to spread though the network and impact the business productivity and reputation. Following Naidoo’s keynote, we joined a panel discussion chatting about creating a balance between organisational productivity and enterprise security in the age of consumerisation. Naidoo was joined by Darren Bilse (Systems and Technology Manager at Spark Schools), Andre Fredericks (CIO at Indie Sanlam) and Greg Lock (Senior Solution Architect at ITEC South Africa); moderating the panel was Saurabh Prabhuzantye (Business Head – MEA at Freshworks). Topics covered in the panel covered everything from how consumerisation of IT has impacted the organisations for which the panellists’ work, to how migration to the cloud has brought both benefits and challenges to IT heads and CIOs around the world, to understanding what you are buying and whether or not it suits your organisation and the needs of your team on the ground; real world problems facing real world organisations. The meet was a great information and knowledge sharing platform, allowing vendors and customers alike to openly share their opinions and experiences and to leverage off of the combined knowledge of South African and global IT professionals.  We would like to thank the Freshworks team for inviting us to participate in this event and look forward to working with them in the future!

“Electricfish” – The latest malware from North Korea’s Hidden Cobra government hacking crew.

May 10, 2019

The Federal Bureau of Investigation (FBI) and Department of Homeland Security (DHS) have issued a joint Malware Analysis Report (AR19-129A) on a new malware variant used by the North Korean government. This malware was detected while tracking the malicious activities of the North Korean-backed hacking group Hidden Cobra (also known as Lazarus) and has been identified as Electricfish. Lazarus Group is a cybercrime group made up of an unknown number of individuals. While not much is known about the Lazarus Group, researchers have attributed many cyberattacks to them over the last decade. A notable attack by the group is the attack on Sony Pictures in 2014, which was the start to one of the largest corporate breaches in recent history. The hackers were able to cripple the Sony network for several days and gain access to valuable insider information including previously unreleased films and the personal information of approximately 4,000 past and present employees. The group was also able to access internal emails and reveal some very speculative practices going on at Sony.  This latest report on Electricfish, published on the US-CERT website, comes with a detailed analysis of one malicious 32-bit executable file found to be infected with Lazarus' Electricfish malware. In this file, the malware appears to implement a custom protocol that creates a connection between the infected host and an external, malicious, destination host, bypassing authentication controls to reach outside of the network. Once a connection has been established, the Electricfish malware is able to funnel internet traffic between the two machines allowing the malicious actors to funnel information collected from compromised computers to servers that they control. The full, detailed report and analysis for the Electricfish malware sample as well as a full list of Indicators of Compromise (IoC’s) are available within the AR19-129A advisory.

#SS19Hack Ideathon young developers aim to protect connected citizens

April 11, 2019

Author: ITWeb Africa "Intriguingly challenging," is how one student described ITWeb's 2019 #SS19Hack Ideathon, held at the Tshimologong Digital Innovation Precinct in Braamfontein this past weekend. The ideathon is a build-up to the third annual cyber security-focused hackathon that will run alongside ITWeb Security Summit 2019 from 27 to 31 May. Organised by ITWeb in partnership with Snode Technologies and Geekulcha, the full-day software development training and brainstorming event hosted a bunch of young tech enthusiasts eager to learn new skills and solve problems. Mixo Ngoveni, founder of Geekulcha, told ITWeb the aim of the #SS19Hack Ideathon, and ultimately the hackathon in May, is to improve cyber security skills, tools and capabilities in the country. "With this one in particular, it is all about protecting the connected citizen." Those in attendance (students, tech entrepreneurs, software and hardware developers, designers and analysts) were welcomed by Kendal Makgamathe, community manager at Tshimologong, and Ivan Regasek, ITWeb CEO. The participants were separated into two teams: the red team (the attackers) and the blue team (the defence). Nithen Naidoo, founder and CEO of Snode Technologies, said the idea behind breaking the teams into two was about the "gamification" concepts, and making it more exciting for both the players and supporters. Ridewaan Hanslo, software engineer, advisor and researcher at CSIR, told the blue team: "You are the people that must find solutions. They [hackers] get glorified by finding problems; that's typically how it works." Steve Jump, head of corporate information security governance at Telkom, was one of the mentors and spoke to students about the importance of "securing by design" when writing software. Solomon Bhala, senior manager of cyber threat detection and response at PwC, gave a detailed credit card fraud presentation that had teams actively participating and asking questions around cyber attacks and credit card fraud. Naidoo noted Snode is working with PwC and a few large security companies to offer all the participants three-month internships so they can take the skills they have learned at the #SS19Hack Ideathon and implement them. They would get to work with knowledgeable cyber security teams, get paid, and potentially become full-time employees of those companies. "So it is a great opportunity not just for us to nurture talent but to source it for other cyber security companies."

Videos

Nithen Naidoo on South African start-up Snode’s use of Big Data analytics for Cybersecurity

February 26, 2018

Nithen Naidoo, Founder and CIO, Snode talks about: what the company does and how; how Snode Guardian can identify cyber-attacks; how the company has been funded; and future plans.

PHP Meetup (16 Jan 2018) – Part 2

February 15, 2018

The second in a series of videos from the PHP Meetup event hosted at the Hello Group on 16 January 2018.

PHP Meetup (16 Jan 2018) – Part 1

January 25, 2018

The first in a series of videos from the PHP Meetup event hosted at the Hello Group on 16 January 2018.

Snode | Who We Are

September 8, 2017

Snode is a data analytics platform that is designed to make the lives of whomever uses it easier, to assist in solving problems that were previously thought impossible, and to ultimately make a fundamental difference in the world as we know it.