Welcome

Welcome to this site dedicated to the IST MODEL Technology, an innovative PATENTED technology designed to guarantee the highest levels of security during communications and transactions over the Internet.

Benvenuti in questo sito dedicato alla Tecnologia IST MODEL, progettata per garantire il più alto livello di sicurezza nelle comunicazioni e transazioni su Internet.
IST MODEL è una tecnologia innovativa brevettata.

IST Model - A short Introduction.pdf

Visualizzazione post con etichetta Fintech. Mostra tutti i post
Visualizzazione post con etichetta Fintech. Mostra tutti i post

lunedì 2 dicembre 2019

DMSniff, Hackers continue to attack POS


A Point-of-Sale (POS) malware which uses a domain generation algorithm to create command-and-control domains on the fly was deployed in attacks against small and medium-sized businesses during the last past four years—since at least 2016—according to a team of security researchers from Flashpoint. It is named DMSniff and it is hard to detect.

Un malaware che attacca i POS (Poit-Of-Sale) e che utilizza un Domain Generation Algorithm (un algoritmo cioè che periodicamente genera un grande numero di nomi di dominio) per creare domini command-and-control. Il suo nome è DMSniff e secondo un team di ricercatori di Flashpoint sta attaccando business delle piccole e medie aziende sin dal 2016.

Reference

lunedì 30 ottobre 2017

Are 95% of HTTPS web servers still vulnerable to MITM attacks?


Encrypted communications are an essential requirement for banks and other financial websites, but HTTPS alone is not sufficient to defend these sites against man-in-the-middle attacks. Astonishingly, many banking websites lurk amongst the 95% of HTTPS servers that lack a simple feature that renders them still vulnerable to pharming and man-in-the-middle attacks. This missing feature is HTTP Strict Transport Security (HSTS), and only 1 in 20 secure servers currently make use of it, even though it is supported by practically all modern browsers.
Each secure website that does not implement an HSTS policy can be attacked simply by hijacking an HTTP connection that is destined for it. This is a surprisingly feasible attack vector, as there are many ways in which a user can inadvertently end up connecting via HTTP instead of HTTPS.

Le comunicazioni criptate sono un requisito essenziale per le banche e per altri siti finanziari, ma HTTPS da solo non è sufficiente per difendere questi siti da attacchi Man In The Middle. Sorprendentemente molti siti web bancari fanno parte di quel circa 95% di server HTTPS che non dispongono di una semplice funzionalità che li rende ancora vulnerabili ad attacchi pharming e Man In The Middle. Questa funzionalità mancante è HTTP Strict Transport Security (HSTS) ed attualmente solamente 1 su 20 server sicuri ne fanno uso, anche se è supportata da praticamente tutti i browser.
Ogni sito web sicuro che non implementa la policy HSTS può essere attaccato semplicemente dirottando una connessione HTTP a lui destinata. Questo è un vettore di attacco sorprendentemente fattibile, poiché vi sono molti modi con cui un utente può inavvertitamente connettersi con HTTP invece che con HTTPS. 

Reference

mercoledì 31 agosto 2016

Cyber-Crime, 1 million victims each day

A study of Cybersecurity Ventures funded by Herjavec Group demonstrates how the cybercrime phenomenon is tremendous rise and that neither the companies nor their CEO are prepared to face it. While the cost for the damages caused by cybercrime in 2015 was 400 billion USD, by 2021 this cost will reach 6 trillion USD. Among the most affected realities are the medical facilities and the Internet of things.

Uno studio di Cybersecurity Ventures finanziato dal gruppo Herjavec dimostra come il fenomeno del crimine informatico sia in tremenda ascesa e che né le aziende, né i loro Ceo sono preparati ad affrontarlo. Mentre la spesa per i danni provocati dal cybercrime nel 2015 è stata di 400 miliardi, di dollari entro il 2021 questa spesa arriverà a 6 trilioni di dollari. Tra le realtà più colpite ci sono le strutture sanitarie e l’Internet delle cose.

(Credit Cybersecurity Ventures, Herjavec Group)

Reference
http://cybersecurity.startupitalia.eu/52725-20160830-infografica-cybercrime-investimenti-cybersecurity

mercoledì 27 luglio 2016

Phishing, probability higher of 50% to encounter a phishing site in 2016

An user is surfing the web. The probability that he will encounter a phishing site during 2015 was 50%, against 30% in 2014. And in 2016 will be above 50%, as stated by Webroot.
They analyzed 27 billion URLs and more than 600 million domains.
The report says that the most phishing-cloned companies are the financial and technology ones.

Un utente naviga nel web. La probabilità di incappare in un di di phishing nel corso del 2015 è stata del 50%, contro il 30% del 2014. E nel 2016 sarà superiore al 50%, come dichiarato da Webroot.
Sono stati analizzati 27 miliardi di URL e più di 600 milioni di domini.

Secondo il report le maggiori aziende bersaglio del phishing sono quelle finanziarie e tecnologiche.

Reference
http://cybersecurity.startupitalia.eu/52291-20160614-pmi-e-sicurezza-phishing-malware-e-trojan-nellinfografica-di-webroot
https://webroot-cms-cdn.s3.amazonaws.com/7814/5617/2382/Webroot-2016-Threat-Brief.pdf

mercoledì 9 dicembre 2015

Mega Trends in Banking, Payments and Fintech

The Fintech (Financial Technology) industry is gaining strong attention. Is is estimated that $ 50 billion is the value of this market for new and disruptive ideas. Main trends are
  1. Cryptocurrency and Blockchain
  2. Innovation and convergence in payments
  3. Focus on customer experience and the evolution of customer-centric initiatives from banks
  4. User authentication and security
  5. New and alternative models of lending (Online lending and peer-to-peer marketplaces)
IST Model can give a strong contribution in above points 2, 3, 4.

L'industria del Fintech (Financial Technology) sta avendo una forte attenzione. Si stima che il valore di questo mercato sia intorno ai 50 miliardi di dollari idee nuove e dirompenti. I trend principali sono
  1. Cryptovaluta e Blockchain
  2. Innovazione e convergenxa nei pagamenti
  3. Concentrarsi sulla customer experience e sull'evoluzione delle iniziative customer-centric dalle banche
  4. Autenticazione utente e sicurezza
  5. Nuovi ed alternativi modelli di prestiti (prestiti online e marketplace peer-to-peer)
IST Model è in grado di offrire un forte contributo nei punti 2, 3, 4.

Reference
http://smartmoney.startupitalia.eu/50737/banche/trend-fintech-banche-disruption/
http://yourstory.com/2015/12/payments-and-fintech/