EVERY DAY, millions of users all over the world get a message that contains a link. The vast majority of those are safe. A few are not. But the distinction between the two lies in the eye of the beholder. This is how cybercriminals function. They exploit the gap between the perception of something being safe and something being a threat. Exactly such a gap has been the focus of Jordan Nicholas’ work throughout the last year.
These figures paint a bleak picture. The majority of successful cyberattacks are phishing ones not because the organizations themselves are poorly guarded against any form of cybercrime, but because attackers found how to completely circumvent this defense through exploiting the very weakness that can never be safeguarded in its entirety the decision made by a human to open the link. For the people of Africa working in their increasingly digitized environment, the problem is even more serious.
Nicholas, a cybersecurity analyst, has made his career on the intersection between protecting businesses from psychological as well as technical threats. His self-developed cyberthreat analysis software CyberScan has been the closest he has ever been to putting his knowledge out there for everyone who requires it.
| “ The best way to prevent an attack is to not allow it even to begin to stop a user from clicking the link in the first place.” |
The point of intervention
CyberScan acts as a preventive measure where it acts at the time of making decisions about using a particular URL that can be dangerous for the system. As opposed to other measures that work by reacting to problems after they have been experienced, CyberScan allows users to decide on their own whether they should access a URL or link. This principle of working forms the basis of Nicholas’s design idea.
CyberScan performs eighteen separate tests on any URL fed into the system, including detecting whether the URL attempts to impersonate brands, which includes URLs pretending to be sites hosted by banks, governments, or technology firms; whether domain names have high levels of entropy, which is associated with malicious domain names generated by algorithms; homograph attacks, which are URLs using Unicode characters to impersonate other domains; detection of files that are considered potentially malicious types; and finally whether there is a URL open redirector, where the URL seems to lead to one destination but redirects to another.
Each of the tests carries a weight depending on its real-world significance, resulting in a composite score which is presented back to the user as one of three judgments: safe, suspicious, or dangerous. Crucially, the heuristics built into CyberScan are not those from an academic study of cybersecurity, nor from a generic database, but based directly on Nick’s first-hand experience in fighting cyberattacks over his four years of enterprise security work.
| WHAT CYBERSCAN DETECTS · 18 independent threat checks ▸ Brand masquerading URLs that impersonate banks, technology corporations, government institutions ▸ Entropy assessment of domain names – identification of algorithmically created harmful domains ▸ Unicode attack on homographs – use of puny code character sets to spoof legitimate domains ▸ File extensions associated with executable files – dangerous URLs that download files ▸ Misuse of URL shortening services – masking harmful sites via redirect services ▸ Open redirects – linking to another harmful site via open redirect ▸ Deep subdomains – common trait in phishing site infrastructure ▸ IP address in URL – clear sign of phishing/malware hosting site ▸ And ten more conditions – each evaluated against the threat landscape |
Usability as a security principle
Among the most stubborn mistakes made by cybersecurity industry is designing tools that people cannot afford using. Enterprise threat intelligence platforms are often priced at several thousands of pounds yearly and demand a specific security department for their operation. Such software is completely out of reach for most people, SMEs, and corporations in Africa or other developing countries.
Nick designed CyberScan precisely considering this problem. First, no registration, accounts, and subscriptions are needed to use this program. Moreover, it does not need any skills to work; it works like any other native desktop software on OS X, Windows, and Linux. Besides, it is distributed free of charge as an open-source software. And the most important thing about CyberScan results is that they are presented in clear and understandable terms; otherwise, they would hardly ever be used.
The solutions must work in the context of actual usage,” says Nicholas. “They cannot be too complicated to implement because otherwise, they will not be adopted. It’s about providing security that is really effective and usable, not something that makes the security experts admire their own creations.”
It shows his overall philosophy, which goes into all his independent initiatives the issue that the difference between enterprise-level security and consumer/small business-oriented one is more a matter of design than anything else. And design issues are solvable.
| “Prevention is better than cure, especially when the prevention does not interrupt any action on your part but rather prevents it even from happening. This is the basic idea behind CyberScan…” |
A tool built for Africa’s digital moment
The relevance of the creation of CyberScan could not be timelier about Africa as a continent. With the rapid growth and adoption of digital finance services, e-commerce, and telecommuting capabilities in the region, there are more potential opportunities for attacks by malicious parties. Such examples include phishing campaigns against mobile payment accounts, fake QR codes in public areas, and malicious links shared through WhatsApp and other social media platforms.
Nicholas, having been born in Nigeria, has made it clear that CyberScan needs to be helpful in the situation described above. Being able to analyze URLs offline makes the program applicable in places with poor internet connections while being free to use removes the financial obstacle in acquiring professional security software from most African organizations.
Furthermore, Nicholas has created two more programs for security purposes which complement the functionality of CyberScan. These are CipherVault, a professional AES-256 encryption service, and MyVault, a password manager that works without an active internet connection.
The shift from reactive to proactive
Industry analysts have commented in detail on how the current dominant approach to cybersecurity, which involves detection and response, will not be sufficient to handle the current threat landscape. The number of attacks, the number of channels through which attacks can be carried out, and the number of targets means that there are too many threats to reactively defend against. However, the industry has reached a consensus on the need to move upstream to make any significant headway against the problem.
In other words, CyberScan reflects this consensus in practice by addressing the issue at the point where it becomes preventable. While Nicholas recognizes that one product cannot solve the problem of phishing, he also believes that proactive protection is possible without being complicated. It should thus be feasible to significantly lessen the risks of targeted individuals and organizations.
“Sometimes, the biggest danger is that which you can’t see. No, it’s the danger that you don’t question. That is why we built CyberScan to encourage questions.”
As more digital technologies emerge throughout the world and Africa takes the next big step towards digitization of its economy, the need for practical innovation to ensure improved cybersecurity cannot be understated. It is for this reason that we must embrace the principles of CyberScan.