Example: bachelor of science

Breaking the Target: An Analysis of Target Data Breach and ...

1 Breaking the Target : An Analysis ofTarget Data Breach and Lessons LearnedXiaokui Shu, Ke Tian*, Andrew Ciambrone* and Danfeng (Daphne) Yao,Member, IEEEA bstract This paper investigates and examines the events leading up to the second most devastating data Breach in history: theattack on the Target Corporation. It includes a thorough step-by-step Analysis of this attack and a comprehensive anatomy of themalware named BlackPOS. Also, this paper provides insight into the legal aspect of cybercrimes, along with a prosecution and sentenceexample of the well-known TJX case. Furthermore, we point out an urgent need for improving security mechanisms in existing systemsof merchants and propose three security guidelines and defenses.

Trojan [11]. This Trojan was initially installed through a phishing attempt. Due to the poor security training and security system of the third party, the Trojan gave the attackers full range of power over the company’s system [10]. It is not known if Fazio Mechanical Services was targeted, or if it was part of a larger phishing

Tags:

  Analysis, An analysis, Targets, Breaking, Trojan, Breaking the target

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of Breaking the Target: An Analysis of Target Data Breach and ...

1 1 Breaking the Target : An Analysis ofTarget Data Breach and Lessons LearnedXiaokui Shu, Ke Tian*, Andrew Ciambrone* and Danfeng (Daphne) Yao,Member, IEEEA bstract This paper investigates and examines the events leading up to the second most devastating data Breach in history: theattack on the Target Corporation. It includes a thorough step-by-step Analysis of this attack and a comprehensive anatomy of themalware named BlackPOS. Also, this paper provides insight into the legal aspect of cybercrimes, along with a prosecution and sentenceexample of the well-known TJX case. Furthermore, we point out an urgent need for improving security mechanisms in existing systemsof merchants and propose three security guidelines and defenses.

2 Credit card security is discussed at the end of the paper with severalbest practices given to customers to hide their card information in purchase Terms Data Breach , information leak, point-of-sale malware, cybercrime, network segmentation, security alert, system integrity,credit card security, EMV, tokenizationF1 INTRODUCTIONB etween November 27 and December 18, 2013, the TargetCorporation s network was breached, which became thesecond largest credit and debit card Breach after theTJX Breach in 2007. In the Target incident, 40 millioncredit and debit card numbers and 70 million records ofpersonal information were stolen.

3 The ordeal cost creditcard unions over two hundred million dollars for justreissuing Corp. is not the only Target of data breaches. Upto the 23rd of September, 568 data breaches are reportedin the year 2014 [1]. The latest significant Breach , , theHome Depot Breach , came to light in September of September 14, it is known that 23 out of 28 HomeDepot stores in the State of Alabama were breached [2].The entire plot could involve a large portion of the 2,200 Home Depot stores in the states and 287 stores overseas,which might result in a larger Breach than the Targetbreach. We list four other significant breaches in thelast two years.

4 The increasing number and scale of databreach incidents are alarming. Sally Beauty Supply discovered in March 2014 that282,000 cards were stolen [3]. Neiman Marcus reported that million cards werestolen during July to October, 2013 [4]. Michaels and Aaron Brother reported that 3 millioncards were stolen from May 2013 to January 2014 [5]. Chang s data Breach occurred from September2013 to June 2014 impacting over 7 million cards [6].Securing massive amounts of connected systems isknown to be technically challenging, especially for re- X. Shu, K. Tian, A. Ciambrone and D. Yao are with the Department ofComputer Science, Virginia Tech, Blacksburg, VA, :{subx, ketian, andrjc4, *K.}

5 Tian and A. Ciambrone contribute equally to the those possess vast networks across the nation,like Target and Home Depot. Target security divisionattempted to protect their systems and networks againstcyber threats such as malware and data exfiltration. Sixmonths prior to the Breach , Target deployed a well-known and reputable intrusion and malware detectionservice named FireEye [7], which was guided by theCIA during its early development [8]. Unfortunately,multiple malware alerts were ignored. Some preventionfunctionalities were turned off by the administratorswho were not familiar with the FireEye system.

6 TargetCorp. missed the early discovery of the paper analyzes Target s data Breach incident fromboth technical and legal perspectives. The description ofthe incident and the Analysis of the involved malwareexplain how flaws in the Target s network were exploitedand why the Breach was undiscovered for weeks. TheTarget data Breach is still under investigation and thereis no arrest made known to the public. Even if the perpe-trators are identified, cyber crimes involving extraditionare notorious to prosecute. We discuss the difficultiesof data Breach discovery, investigation and prosecutionwith respect to legislation and international earlier incident, TJX data Breach in 2007, is presentedas the precedent for arresting and sentencing criminalscommitting financial we observe an increasing number of data breaches,these incidents bring us to rethink the effectiveness ofexisting security mechanisms, solutions, deploymentsand executions.

7 Credit card Breach has a huge negativeimpact on every entity in the payment ecosystem, includ-ing merchants, banks, card associations and this paper, we provide several insights into weaklinks in the payment ecosystem, specifically in existingsecurity techniques and practices. We give several bestpractice suggestions for merchants and customers toenforce their data security and to minimize information2 SeptemberAttackerscompro-mised 15 Attackersbroke intoTarget snetworkand testedmalwareon 27 Attackersbegan tocollectcredit 30 POS mal-ware 2 Attackersbegan tomove creditcard 12 Departmentof 1.

8 Timeline of the Target data Breach (2013). contributions of our work are summarized asfollows. We gather and verify information from multiplesources and describe the process of the Target databreach in details (Section 2). We provide an in-depth Analysis of the major mal-ware used in the Target Breach , including its designfeatures for circumventing detections as well as themarketing of the malware (Section 3). We discuss the complexities and challenges indata Breach investigation and criminal prosecution,specifically from the legal perspective. We describethe TJX Breach in 2007 as a precedent for arrestingand sentencing cyber criminals (Section 4).

9 We provide three security guidelines for merchantsto enhance their payment system security:i)pay-ment system integrity enforcement,ii)effective alertsystem design, andiii)proper network segmenta-tion (Section 5). We discuss the current status of credit card security,point out problems in the credit card system, andgive customers best practices to hide their informa-tion in purchase transactions (Section 6).2 THETARGETINCIDENTThe systems and networks of Target Corp. were breachedin November and December, 2013, which results in 40million card numbers and 70 million personal recordsstolen [9]. Multiple parties get involved in the federalinvestigation of the incident.

10 The list includes UnitedState Secret Service, iSIGHT Partners, DELL Secure-Works, Seculert, the FBI, etc. In addition, companies likeHP, McAfee and IntelCrawler provide Analysis of thediscovered malware, , BlackPOS, and the marketingof the stolen Breach Into TargetThere are multiple theories on how the criminals ini-tially hacked into Target , and none of them have yetbeen confirmed by Target Corporation. However, theprimary and most well-supported theory is that theinitial Breach didn t actually occur inside Target [10].Instead, it occurred in a third party vendor, Fazio Me-chanical Services, which is a heating, ventilation, andair-conditioning to this theory, we present the timeline ofthe incident in Fig.


Related search queries