<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Security Detail &#187; oil industry</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/security-detail/tag/oil-industry/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/security-detail</link>
	<description>Tony Bradley's take on the latest vital IT security news.</description>
	<lastBuildDate>Mon, 29 Apr 2013 17:39:02 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>&#8220;Night Dragon&#8221; Attacks Oil Industry</title>
		<link>http://itknowledgeexchange.techtarget.com/security-detail/night-dragon-attacks-oil-industry/</link>
		<comments>http://itknowledgeexchange.techtarget.com/security-detail/night-dragon-attacks-oil-industry/#comments</comments>
		<pubDate>Fri, 11 Feb 2011 14:06:36 +0000</pubDate>
		<dc:creator>Tony Bradley</dc:creator>
				<category><![CDATA[china]]></category>
		<category><![CDATA[energy sector]]></category>
		<category><![CDATA[mcafee]]></category>
		<category><![CDATA[oil industry]]></category>
		<category><![CDATA[precision attack]]></category>
		<category><![CDATA[targeted attack]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/security-detail/night-dragon-attacks-oil-industry/</guid>
		<description><![CDATA[A report published by McAfee illustrates in detail an extensive pattern of precision attacks targeted specifically against the oil industry. The revelation from McAfee is yet another example of the rising trend of malware as a tool for corporate espionage, and the threat of state-sponsored cyber attacks. The McAfee report&#8211;titled Global Energy Cyber Attacks: &#8220;Night [...]]]></description>
				<content:encoded><![CDATA[<p class="MsoNormal" style="margin: 0in 0in 10pt"><span style="font-size: small"><span style="font-family: Calibri">A report published by McAfee illustrates in detail an extensive pattern of precision attacks targeted specifically against the oil industry. The revelation from McAfee is yet another example of the rising trend of malware as a tool for corporate espionage, and the threat of state-sponsored cyber attacks.</span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt"><span style="font-size: small"><span style="font-family: Calibri">The McAfee report&#8211;titled <em><a href="http://www.mcafee.com/us/resources/white-papers/wp-global-energy-cyberattacks-night-dragon.pdf"><span style="color: #0000ff">Global Energy Cyber Attacks: &#8220;Night Dragon&#8221;</span></a></em>&#8211;states, &#8220;Starting in November 2009, coordinated covert and targeted cyber attacks have been conducted against global oil, energy, and petrochemical companies. These attacks have involved social engineering, spear phishing attacks, exploitation of Microsoft Windows operating systems vulnerabilities, Microsoft Active Directory compromises, and the use of remote administration tools (RATs) in targeting and harvesting sensitive competitive proprietary operations and project-financing information with regard to oil and gas field bids and operations.&#8221;</span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt"><span style="font-size: small"><span style="font-family: Calibri">The implications are ominous. The computer and network security industry operates on a primarily reaction-based model. Attackers create threats, and security vendors discover them and create defenses to guard against them…after the fact. If<span>  </span>the attacks fly under the radar, though&#8211;remaining undiscovered&#8211;then there is little that most of today&#8217;s security solutions can do to detect or evade them.</span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt"><span style="font-family: Calibri;font-size: small">Attacks such as this&#8211;like the </span><a href="http://www.pcworld.com/businesscenter/article/187119/dont_kill_the_messenger_blaming_ie_for_attacks_is_dangerous.html"><span style="font-family: Calibri;color: #0000ff;font-size: small">&#8220;Operation Aurora&#8221; attacks</span></a><span style="font-family: Calibri;font-size: small"> against Google and others (also a China-based effort), or </span><a href="http://www.pcworld.com/businesscenter/article/206320/stuxnet_compromise_at_iranian_nuclear_plant_may_be_by_design.html"><span style="font-family: Calibri;color: #0000ff;font-size: small">the Stuxnet worm</span></a><span style="font-size: small"><span style="font-family: Calibri"> ostensibly engineered specifically to compromise the nuclear capabilities of Iran&#8211;are much harder to defend against. McAfee explains, &#8220;Our experience has shown that many other industries are currently vulnerable and are under continuous and persistent cyber espionage attacks of this type. More and more, these attacks focus not on using and abusing machines within the organizations being compromised, but rather on the theft of specific data and intellectual property.&#8221;</span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt"><span style="font-family: Calibri;font-size: small">Technology has evolved, and cyber attacks have matured. Organizations can&#8217;t just rely on the traditional firewall and antivirus software model to protect corporate secrets and other sensitive information, or to guard against subversive coordinated attacks. IT and security admins need to be more proactive about vulnerability and risk assessment of critical assets, and more vigilant about safeguarding sensitive information and </span><a href="http://www.zecurion.com/zgate.php"><span style="font-family: Calibri;color: #0000ff;font-size: small">preventing it from being leaked</span></a><span style="font-size: small"><span style="font-family: Calibri"> or compromised. </span></span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/security-detail/night-dragon-attacks-oil-industry/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
