Showing posts with label blockchain. Show all posts
Showing posts with label blockchain. Show all posts

Tuesday, 13 March 2018

AI, NLP, Blockchain: Yes, We’re on The Buzzword Bandwagon but Here's Why


- Simon Bain, BOHH Labs CEO

Like every year, there are certain technologies that get more attention than others. Right now, some of the biggest ones making a good run include Artificial Intelligence (AI), Natural Language Processing (NLP) and Blockchain. Based on the number of companies or new products that have come out of the woodwork using these technologies, it’s clear people love to use buzzwords and tout they are using the hottest, most innovative technology on the market to gain competitive edge and create the illusion of being a forward-thinker. However, many companies jump on the buzzword bandwagon simply because it is something popular everyone is doing, and so they do it too. While this may just sound like a lame popularity contest giving you nightmares of your high school days, when this strategy is applied to something critical like data security, there can be serious ramifications for companies laying all their eggs in one basket and settling for solutions that are hot at the moment.

Before I go on about how bad it is to jump on buzzword bandwagons, I first must address that at BOHH Labs we do apply the AI, NLP and Blockchain technology buzzwords taking the industry by storm. However, what makes our approach unique is that we do not rely on just one of these, but instead use them in an interconnected way that helps us ensure we can secure all user, applications and data access. So yes, we do fall in to the bucket of one of those companies using buzzwords, but we leverage the benefits that make each one of them unique in to a full-encompassing security solution. Below is a breakdown why and how we apply each of these technologies:


  • Artificial Intelligence (AI):  AI uses a compound set of algorithms to detect patterns and predict outcomes from a large amount of data online, as such, the self-learning capabilities and ability to recognize patterns and anomalies within them, makes AI a great tool to detect cybersecurity threats within the network in real time. We use an AI engine to do threat analysis and to prevent intrusions. Our AI manages ports, interacts with and processes user requests, and maintains a secure connection by learning, identifying and removing any unwanted traffic before it is passed along and gets access to any of the backend applications or databases. 
  • Natural Language Processing: NLP is a great tool to connect the gap between human and machines as technology continues to advance and will have many advantages to streamlining processes. Our NLP is critical to ensuring the BOHH solution works properly. It works like most human brains work. When a request comes in, it determines if it is a command or question, then it does entity recognition, looks and finds the answer from the correct database(s), performs any additional processing math, and then formats the response and passes it back. 
  • In-Memory Distributed Blockchain Ledger: The underlying technology of blockchain offers great potential to bring more granularity to areas where you have an open network of millions of transactions. It offers the potential of an unchangeable, universally visible ledger that creates its own audit trail, decreasing the possibility of backdoor transactions. We use an encrypted In-Memory Distributed Blockchain Ledger. Unlike other standard databases, the ledger fields do not hold complete data. This means that the database service requires less memory and processing power, less management of resources for the database itself and controls field level access of data down to an individual or device level. The power of this is that you can have multiple devices accessing a single database and table, yet each can only access a single field managed by that database regardless of the SQL query that has been sent. 

There you have it. To sum up, I believe it is my role as a technologist to help companies understand why it is important to invest in security technologies that will make an impact on their solution, and not just apply something new that is hot now.

Tuesday, 28 November 2017

The BOHH Breakdown, Part 13: BOHH Predicts the Top Security Trends for 2018


In our last post, we reviewed some of the best security techniques being used to keep our data protected and that we are grateful for in honor of Thanksgiving. Today, we will shed some light on what the team at BOHH Labs believes will be the hot topics in 2018 and share our predictions.

Every year experts turn to their magic crystal ball and share their thoughts on predictions they have for the upcoming year. Will we see the same trends from 2017 repeat themselves or we will see new ones develop in 2018? Below our experts from BOHH Labs weigh in on the discussion and offer their predictions for what’s ahead.

Blockchain will be the Heart of The Finance Industry:
It’s no secret that blockchain is the hot new technology, and we will see this technology be embraced   predominantly by the financial industry. Because of its decentralized and distributed nature, more financial services institutions are looking at blockchain to replace the centralized business model. As an example, KPMG, one of the “Big Four” accounting firms, recently just joined the Blockchain Advocacy Group.

As Bitcoin is based around blockchain technology, and it has seen significant growth in value during 2017 event though it’s an unregulated currency, will continue to increase when security is a potential issue or will it fall off the tracks?


NASDAQ Advising People to Jump on Security Boards:

We all know security breaches are a big deal, so why aren’t more board of directors versed in the area? As the oversight of an organization’s value and growth, it’s critical for security to become a business priority and an integral part of their organizations’ daily operations. This means a companies’ cybersecurity activities must hold as much weight in decision-making in the same way as they do in the financial ones. As such, in 2018, we will see NASDAQ advise more security expert to join companies’ boards, so they can help companies navigate to better long-term performance and success.

Website Attacks Become a Bigger Target:
One of the type of attacks that we will see gain more traction this year is the website attack. With the growing use of online services (checking accounts, merchant accounts and Point-of-Sale (POS) systems, etc. now going through the web) the risk of attacks is large and has the potential to affect any institution using these services, as it opens access to institutions’ backend databases, document stores and applications all within easy reach. 

Because an attacker gains access to the website through a hijack of a user’s requests and then makes a simple change of code to redirect payment information their way, while NOT stopping the requests correct path, this type of attack is very hard to find, but incredibly easy for attackers to undertake.

The website is no longer just a marketing tool. It has become a business tool, and as such, it now needs to be properly protected from attacks and placed inside a firewall, and preferably completely encrypted, so that attackers are unable to change, manipulate and delete code to their advantage.

Continued Chat Bot Growth:
The growth in the business use of chat bots will continue to increase based on their interactive nature and their capabilities to complement existing call center activities by taking away mundane tasks. However, with their interactive capabilities and the ability to use location services to reserve a table in your proximity and even order an item such as a coffee, it is becomingly increasingly important that all chat bot transports are secure.  Similar to website data breaches, should intrusion attacks penetrate the chat bots, user trust will be lost as well as the possible loss of confidential data.

Public Cloud Adoption will Continue to Challenge Enterprise Companies:
While Cloud adoption is the goal of most global enterprise companies to help improve their IT speed, business agility, and modernize existing on-premise applications such as ERP, Finance and HR, adoption will be limited due to the time and money needed to implement cloud security standards that emulate enterprise on premise infrastructures.  

By using a secure gateway to a Public cloud provider, enterprise accounts could accelerate their cloud deployments and benefit from the economics of cloud, plus have the ability of choice and move Cloud providers as the business sees fit.

IoT Attacks Will Keep Growing:
We will continue to see companies scramble to implement security for IoT devices and applications. We’ve already seen the significant and expansive impact that hacks on IoT devices can have and it will only continue as we move in to 2018.

General Data Protection Regulation: 
Effective from 25th May 2018 companies will need to comply with the General Data Protection Regulation (GDPR) which applies to all companies that use or process data in the European Union.  As several analyst articles suggest, only 25% of companies are expected to be in full GDPR compliance in May 2018, and as a consequence of this, the initial fine or penalties imposed on a none compliant company will be significant to warn other companies of its importance.

Now that we’ve highlighted some of the major security themes we predict will take center stage in 2018, come back next Tuesday when we will share some tips to stay cyber safe in the holiday shopping season.

Friday, 10 November 2017

Weekly News Roundup


Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.

Fake WhatsApp app downloaded more than one million times

A fake version of the WhatsApp messenger app was downloaded more than a million times from the Google Play Store before it was removed. According to users, the fake contained ads and could download software to users' devices. Read more…

Senators Blast Equifax and Yahoo for Massive Data Breaches

Both Yahoo and Equifax took the stand this week to address the major customer data breaches that happened under their watch and what responsibility their companies had for the historic data breaches that saw billions of Americans' privacy compromised. Read more…

What's going on with Ethereum? $280m in cryptocurrency 'lost' amid security scare

Approximately $280m worth of the cryptocurrency Ethereum has been frozen in time – and potentially lost forever – after an unidentified developer accidentally triggered a critical bug in a shared code library used by digital wallets maintained by Parity Technologies. Read more...

2.7M Verticalscope credentials compromised

The Canadian web forum manager Verticalscope has again been hacked with 2.7 million user accounts being affected this time. The latest incident takes place about one year after the company reported that 45 million user credentials had been compromised. Read more…

Friday, 7 July 2017

Weekly News Roundup


Too busy working all week to keep up with the most interesting stories coming out of the technology and security industries? Below are our recommendations for a roundup of the top stories happening now that you need to know.

Breached Bitcoin Bithumb bosses blame bod's BYOD

South Korean cyber-cops are probing a hacking attack on Bithumb, one of the world's biggest Bitcoin exchanges. Miscreants were able to get hold of personal information of roughly 32,000 Bithumb users, or three per cent of the exchange's user base. Read more…


CopyCat Android malware infected 14 million devices, rooted 8 million last year

CopyCat Android mobile malware was able to infect over 14 million devices last year and root eight million of them, researchers have revealed. Read more…


'NotPetya' Hackers Demand $256,000 In Bitcoin To Cure Ransomware Victims

It looks like the hackers responsible for the massive ransomware outbreak that crippled Ukraine last week and infected some of the world's biggest industrial companies, from Maersk to Merck, are posting messages demanding more Bitcoin to unlock victims' files. They're after 100 Bitcoin, currently worth an astonishing $256,000. Read more…

Kaspersky offers to turn over source code to U.S. government

Kaspersky said the U.S. government can audit its source code, a move meant to prove Kaspersky Lab is not in bed with the Russian government. Read more…


Thursday, 4 May 2017

Blockchain: Breakthrough or Bust?


Blockchain is emerging as one of the hottest cybersecurity and information-sharing solutions being talked about now, but is all its promise in the fact that it is the latest craze to hit the market and people want to be compliant or is it a breakthrough waiting to happen?

As with most things in life, it’s a little of both.

Let’s first start with the positives. 

  • The core idea of blockchain is a great concept because it has made people start thinking about security more seriously. Let’s be honest, most companies are simply playing lip service to security. “Yes of course our systems are secure;” “We use the latest security systems;” “We employ the most up to date security systems and policies…” But really, the word security has been used as an excuse not to go in to details or to throw off blame and recrimination. However, blockchain has piqued the interest of many consumers – they are asking their companies about blockchain and how it could impact their environment. Simply put, whether buzz or not, blockchain is making people think more seriously about how their data is being managed. 
  • Another area that blockchain has some very promising benefits is in the cryptocurrency sector where you have an open network of millions of transactions. In basic terms, blockchain enables a single version of transactional truth: an unchangeable, universally visible ledger that creates its own audit trail, decreasing the possibility of backdoor transactions that most digital currencies face. Essentially, it can easily and privately move and store digital transactions securely, and the more widespread the network, the more difficult blockchain makes it to tinker with the data.

With that being said, it is too soon to tout blockchain as the end all be all to our security woes. There are still several areas that need to be addressed.

  • Too many people are jumping on the bandwagon and hype of blockchain. People are looking at it as the only mechanism and not looking at what the actual security issue is. It is a great tool for helping the security of transactions and making sure transactions are secure, but it won’t secure up the end databases. Blockchain focuses on securing the external world and exchanges but it does not look at the underlying security of the data.
  • Users put a lot of trust into the fact that these digital currency exchanges based on blockchain have the right security protocols in place, yet time and time again they have been shown that they are not safe and your money could easily be stolen.
  • There are no regulations or reimbursement structures in place yet. When blockchain and cryptocurrencies experience security issues, whose ownership is it under to cover customers in the event of a breach? There is still a lot that remains unsettled when it comes to regulation statuses, and there are no current rules around offering insurance on digital currencies. The way blockchain based-transaction are set up now, no one will step in to help and that is too great a risk to have the public exposed to.

While there are both advantages and disadvantages to blockchain, one thing is clear: as an industry, we need to look at all the solutions available, not just lay all of our eggs in one, and find ways to secure our information end-to-end and not just settle for the solutions that are hot for the moment. So stay-tuned and let's see where the blockchain buzz goes.