Showing posts with label Security. Show all posts

How Lack Of Human Resource Is Threatening The Cybersecurity Realm


Maintaining a Cybersecurity department is the need of the hour for the companies. Human Resource has a major impact on the Cybersecurity and it can be perceived from the situation that there has been a decline in the number of recruitments due the lack of skillset and talent, despite the numerous high-salary job opportunities.
We are humans and using us to accomplish a goal is called Human Resource (HR). The topic concerning to maximize the potential of Human Resource has been prevalent and to my utmost concern, the human race has to input heavy efforts in order to pace up with industry’s increasing talent demands.
Cybersecurity – one of the major fields where the human resource is losing its credibility – is for protecting computer hardware, software, and information stored from potential attacks like DDoS, phishing, tampering, and many more. But in recent years, humans appointed in the Cybersecurity field have shown an acute lack of determination, when it comes to acceptance of new skills as well as consistency in a rapidly changing atmosphere, that requires an individual to remain up-to-the-minute with latest practices and technological trends in the Cybersecurity space.
In a keynote presented by Mathew Rosenquist, a Cybersecurity Strategist at Intel Security, he focussed on how Human Resource is playing a pivotal role in shaping new age Cybersecurity workforce. Despite enormous efforts made by various Cybersecurity organisations and the “digital security field outpaced IT positions by double and twelve times the rate of the overall job market”, it is easy to decipher the situation that a qualified workforce is like a day dream for the security industry, with an estimate of 2 million unfilled positions by the end of 2017.
While speaking at the ICT Educators Conference this month, Rosenquist emphasized on how the current education system can upgrade its course structure by introducing a formal degree program for CyberScience related syllabi. He also discussed that the sole focus on training an individual to acquire proper knowledge and unvarying skill set will help the individual to be an efficient and reliable Human Resource.
Another side of the coin is the diversity of workforce required in the Cybersecurity workspace. There is a rising demand of people with varying interests and capability to think “out of the box” in tricky environments. Rosenquist discussed Intel’s continuous efforts to diversify its workforce, be it on ethnic, gendered, or based on skill level. Intel has plans to invest $300 million for that purpose.
It is a great example of how a corporation can make a difference in the hiring, progression, and retention of a diverse workforce, contribute to building a sustainable flow of talent, and directly support other organizations doing the same.John Pescatore, Director of emerging security trends at SANS Institute
The keynote (presented at ICT Educators Conference) briefs the effectiveness of diverse workforce when it comes to solving problems, finding an error and showing creativity. An individual can take advantage of the competitive hiring process, exposure to executive levels, and significant salary bumps with an average inflation of $12000 than any other computer field.
Intel’s Diversity In Technology Initiative
Intel flagged off its Diversity and Inclusion initiative in January 2015 with a goal to represent a completely diverse workforce by the end of the year 2020. The company will utilize its resources to increase the percentage of women and underrepresented minorities.
According to the Diversity in Technology mid-term report published on May 12, 2015, in the first half of the year 2015 Intel managed to outperform its predefined goal of 40% – 1275 diverse employees out of a total of 2944 hiring in the United States which account for 43.3% – by the mid-year. Exploring the diversity of the workforce yields 35.2% (1035) women, 4.7% (139) African American, 7.5% (222) Hispanic, and 0.3% (9) Native American.

Intel is determined to work on the following key programs:

Achieve full workforce representation through focused hiring and retention programs.

In December 2014, Intel’s US workforce comprised of 23.5% (11386) women employees which increased to 24.1% (12916) by the end of July 2015. A similar increase was observed for African Americans, Hispanics, and Native Americans.
Intel maintains a Diversity Dashboard which is used to keep an eye on the number of new hires and fires to track the progress of women and underrepresented minorities. The Dashboard is regularly synchronized across all Intel divisions and regularly shared with the CEO, VPs, and the executive team.
In the case of leadership roles, by July 2015, the workforce representation was 17.1% (68) for women and 6.0% (24) for underrepresented minorities.
To balance hiring, we have increased focus on advancing our inclusive culture by utilizing fair processes and practices, such as rigorous reviews of annual appraisal parity and pay audits, as well as by increasing investments in our manager and leader capabilities to ensure that the unique skills and experiences of our entire workforce are fully leveraged.
— the report says.

Grow the pipeline of technical talent for the industry at large:

Intel will invest an amount of $5 million over the next four and a half years as per an MOU signed with Oakland Unified School District. The funds will be utilized to improve the number of Computer Science and Engineering graduates by boosting the number of students from 100 to 600. Intel will put forward its efforts to bring volunteer participation of its employees to accomplish this goal in addition to offering employment options to technical graduates from the Oakland district.

Improve diversity in our supply chain and vendors:

With plans to focus on Indirect Service Segment, Intel eyes an approximate investment of $600 million in order to satisfy its intentions to improve supplier diversity. Further aid will be accomplished by performing a collaborative operation with Capital Partners, thereby, increasing technology sector representation in terms of diversity and inclusion.

Invest in diverse entrepreneurs of emerging technologies:

A $125 million Intel Capital Diversity Fund is aimed at rising technology startups which come under the eligibility criteria of a woman or an underrepresented minority as the CEO or founder, or having, at least, three women in leadership roles. The fund announced on June 9, 2015, has been utilized to power Brit + Co, Care Cloud, Mark One, Venafi.
Intel Captial was founded in 1991, and since then, it has been a cash card to around 1400 companies spanning over 57 nations with the total investment amounting to $11.4 billion.
We are proud to take a leading role toward broader participation in technology entrepreneurship and employment. With this new fund, Intel Capital is committed to investing in the best talent from a myriad of backgrounds to cultivate innovations that serve the needs of a diverse public.
— said Intel Capital MD Lisa Lambert, who is leading the Intel Capital Diversity Fund.

Support women in gaming:

Gaming is not considered as a woman’s deal and they don’t contribute much to the male dominated International Game Developers Association (IGDA). Intel made an attempt to make justice with their Diversity in Technology initiative by sponsoring Gamescom, E3, and Nordic Games conferences in addition to creating the game-design seminar for girls titled as Intel Two5Six Scholar Program.
There are some female warriors in the gaming realm such as Katherine Gunn aka Mystik is an American professional gamer who has bagged credits in the Guinness Book of World Records 2016 Gamer’s Edition. She won the second season of WCG Ultimate Gamer in 2010 and is famous for DOA4 and HALO: Reach.

The Crisis Situation

If we time travel four or five years back, the technology companies were not that much concerned about the security aspects, the Cybersecurity division was often included under the IT department. But the pace of time has forced them to think about a separate security division, which is the need-of-the-hour.
“This has resulted in increased salaries and a shortage of qualified [staff for] small to medium enterprises in the marketplace,” – says Douglas Saylors, Director at Information Services Group (ISG) based in Stamford, Connecticut.
One out of the hundreds of concerns faced by Cybersecurity firms is finding talented employees. However, the fact can’t be denied that the complicated and tedious recruitment process poses as an imminent cause to increased number of unfilled positions. Hence, an intelligible perspective should be displayed upfront for a potential recruit.
Talking about the training and skill set aspect, does it really matter?
Intel’s $300 million investment to transform the academia is a clear long-shot but if we have to make a decision on a short-term notice, the lack of skilled workforce and above that, untrained employees may act as a cause to the unreliable future of cybersecurity space dealing with digital attacks every now and then.
The reason so many enterprises need more security people is because they are doing basic things wrong in IT — not keeping up with patches and misconfiguring things.John Pescatore, Director of emerging security trends at SANS Institute
Companies based in the United States often try to lure brains residing in India and other parts of the world, with their H1B VISA schemes and hard cash salary packages. But that’s not a fool-proof solution for the future of this vast field, which is finding it hard to fill the security professional chairs.
These companies should understand the value of proper training, and understand that IT professionals often lack a broader perspective of the Cybersecurity space.This will allow the transformation of the current networking staff into security specialists after proper training. An internal evaluation that would acknowledge the companies whether their security experts can deal with up-to-the-minute cyber-threats is a must.
Write your views in the comments section below.
Thursday, February 4, 2016
Tag :

Faking the TCP handshake


Faking the TCP handshake


To the best of our knowledge, this attack is a new finding. Asking around, people assume the TCP handshake verifies the IP addresses on both sides. This attack shows that this is not actually true.
In a collaborative project for the Fontys University of Applied Sciences, Raoul Houkes and I researched different ways to attack TCP, either at implementation or protocol level. What we found was a protocol-level attack, affecting all correct implementations.

The TCP handshake works like this, with A being the client that is connecting to B:
A: Hi B, I'm A, send number 5.
B: Hi A, I'm B, 5, send number 3.
A: Hi B, I'm A, 3, send number 6. I'd like example.net.
B: Hi A, I'm B, 6, send number 4. Here comes the data: ...

After this, A can send data to B and B can send data to A. For each byte of data they send to each other, their numbers increase. This is to keep track of whether all data has been received by the other party, to ensure reliable transmission.

When this was designed in 1981, security was no priority. The ARPANET efficiently fit in a single list and they needed a protocol to send data without worrying about retransmitting on errors, checksumming to check for errors, keeping packets in order, etc. TCP solved all of this.
These numeric fields, called the 'sequence' and 'acknowledgement' numbers, are currently used for security as well as reliable transmission. This causes two problems:
  1. The fields are not particularly large (32 bits).
  2. Due to their dual purpose, incorrect numbers have to be discarded without corrupting the connection. In other words, you can send incorrect acknowledgement numbers and subsequent packets with a correct acknowledgement number will be accepted just fine.
We combined these two properties into our attack, which would look roughly like this, where A is sending packets to B:
A: Hi B, I'm C, send number 5.
B: Hi C, I'm B, 5, send number 3.
A: Hi B, I'm C, 1, send number 6. I'd like example.net.
B: Hi C, I'm B, that's incorrect. Close the connection please.
A: Hi B, I'm C, 2, send number 6. I'd like example.net.
B: Hi C, I'm B, that's incorrect. Close the connection please.
A: Hi B, I'm C, 3, send number 6. I'd like example.net.
B: Hi C, I'm B, 6, send number 4. Here comes the data: ...

In this example, host A never receives any of B's messages and B does not know that it's responding to a fake IP address. Host A is faking its IP address into C.

One prerequisite for the attack is that the real C will not actually send "Huh what is going on"-packets (or RST packets), but that is easy: either take a non-existent C (e.g. 0.0.0.0) or take advantage of firewalls (clients are typically behind a stateful firewall, or NAT, or both).
The time B will wait for C (or any other client) to confirm the connection is limited. On a Linux 4.2 kernel I tried this and it turned out to be 20 seconds. After these 20 seconds you need to start over (send another SYN), but this does not make any difference since the chosen numbers are completely random.

The cost of the attack? On average it takes 120GB of network traffic (counting 60 bytes for the ethernet header, IP header and TCP header combined) to create a spoofed connection. You could get unlucky and need 200GB of traffic, but it's equally likely to get lucky and only need 72GB.
A quick search reveals many VPS systems with 1gbps bandwidth for very little money. If you take full advantage of the available bandwidth, the attack takes 17 minutes and 11 seconds on average.
Usually you will want to inject a payload, for example to send a command. This command needs to be appended to the existing data, making the attack larger. For example sending "GET / HTTP/1.0\n\n" takes on average 152GB or 20 minutes. This will show up in the access logs as a perfectly normal connection though.

Other examples of this attack include getting around black- or whitelists, for example on management interfaces of certain systems. This was really popular in the 90s, but many are still around and plenty new applications still work this way.

Proof of concept

What is a research project without a proof of concept? Here are screenshots from Wireshark, a packet dump, and the code that was used.


I filtered out the relevant packets, as captured by the target: 192.168.36.17. The first packet is the initial hello, sent by 192.168.36.11, spoofing 192.168.36.18. Our target responds to the fake IP address, and what happens next is that the tool starts guessing the right acknowledgement number. Note the time jump from 0.x seconds to 8.x seconds, here I filtered out a number of attempts. At some point, the number goes from 2^32 (4.x billion) to zero, this is because Wireshark gives us relative numbers. It also means we've found the right number. Relative acknowledgement number 1 is the one we need to have! After receiving that one, the SSH server responds with its banner, as an SSH server always does upon receiving a valid TCP connection.

Here is the conversation in some more detail:


The random number picked by the server is 0x0006943f (or 431167).


At some point, our script comes across 0x00069440 (or 431168), which is the right number because we need to send what we received plus one.


In response to that, SSH gives us the banner that is always sent at the beginning of a valid connection.
The original packet dump is only 15 seconds long because I captured 15 seconds around the event before rotating logs. Sounds like nothing, but it's 5 544 384 (5.5 million) packets and almost half a gigabyte. If you want to see this, you could just run the attack and see for yourself.
The packet dump that is visible above can be downloaded here:
And finally, the code that was used to perform the attack can be downloaded here:
As a true proof of concept, it's specifically written for this purpose and the code is not made to be maintainable ;)

Conclusion

The attack is difficult to mitigate due to the nature of the TCP protocol. Only wildly incorrect guesses at the acknowledgement number could be rejected as invalid and could be used as a reason to close the connection, but even then that leaves a large enough window to exploit.
To authenticate both sides of a connection, additional security such as TLS needs to be used. Even if the certificate is not authenticated, any encrypted TLS session will do because there is additional data that needs to be received by the client. Spoofing becomes infeasible.
Lesson of the day: never use IP address-based authentication, don't trust IP address whitelists, and use security protocols when you need security (or non-repudiation).
Tuesday, December 1, 2015
Tag :

Canada Faced Challenge Against Protecting From Cyber-Attacks


An employee monitoring cyber attacks and other security breaching activity from the hackers such as Financial institutions, Governments, and big business firms.


Canada is one of the most Cyber security threat affected countries from the last six months, now Canada dawdle apart from the U.S., Britain and other developing countries in protecting their own citizen and financial business institution from cyber attacks in a regular basis, the lack of strategy and system utility in Canada make more suffer for the government.


 In a very productive way the number of cyber attacks increasing every day. Canada is one of those countries who currently facing the situation of cyber attacks, and lack of defending the attacks as well. Katherine Thompson from Canadian Advanced Technology Alliance said, “We’re failing, we’re failing behind,” CATA is one of the largest private sectors with the high-tech advocacy group in Canada.
Canada just recently chosen party leader from the federal election but none of the leader at that mean time didn’t even discussed about the cyber-security threat approaching in the country, they didn’t even said that they need to focused over the development in Cyber Security for the country, Katherine Thompson said “We cannot continue down the path which currently we are going on right now,” also she said, “We just went through a very long federal election where not one of the major party discussed cyber-security.” She told to CBC News Reporter.

Canada Faced Challenge Against Protecting From Cyber-Attacks

The Canadian government has invested very low budget in protecting their citizen and other financial, Business sectors and private institution computer system from cyber attacks, it is around $245 million investment since 2010 to till date, the cheap computer equipment and very fewer numbers of equipment supplied to the government institution.
It has likewise reserved $142 million throughout the following five years to handle digital dangers, especially against basic base. Yet, pioneers in Canada’s policing, IT and digital security parts say the government methodology is engaged basically on national security dangers and does little to battle the emotional development in email tricks, online blackmail and ruptures at corporate PC systems.
Canadians are likewise to a great extent oblivious about the extent of cybercrimes given the nation has no focal organization to track online tricks and pernicious electronic assaults. Besides, are no government laws to constrain organizations to uncover hacks, security ruptures, robberies of information or cash so the overall population has deficient learning of which organizations have been bargained.
“Individuals having their personality debilitated, or having their PCs tainted, scrapes secured for payoff, those sorts of things, the normal police headquarters doesn’t know how to react to that,” says Norm Taylor who drives an official preparing system for the Canadian Association of Chiefs of Police. “The outcome is, it’s not being reported. What’s more, the general population is neither reporting, nor are the police truly doing much in the method for effort to evaluate those sorts of occurrences,” he says.
The gathering distinguished “the pressing need to build reporting of digital violations to police,” and indicated Australia’s ACORN program (Australian Cybercrime Online Reporting Network) as a model for gathering subject protests so that police and industry can screen patterns, foil sorted out criminal gatherings and organize episodes for further examination. The FBI in the U.S. runs a comparative project called “IC3”, alluding to its Internet Crime Complaint Center, which a year ago alone got 269,000 objections about cheats, email tricks and online blackmail. That incorporated around 4,000 protests from Canada.
Thursday, November 26, 2015
Tag :

How To Become A Pro Gamer – 8 Tips From The Pros


Gaming has come a long way since the days of Pong, Duck Hunt and Pac-Man, when competing meant getting the top score at the local arcade. Electronic sports, or eSports, describes the organized video game competitions (with cash prizes) that are quickly rising in popularity as more gamers become fierce pro competitors.
Now pro gamers are competing around the world — some for winnings in the millions — at events such as the Major League Gaming (MLG) circuit, The International Dota 2 championship and Intel Extreme Masters.
IEM San Jose 2014
MLG built dedicated arenas across the country to host and stream professional gaming events, and has scouts and communities to find the best untapped players.
Gaming is serious business.
So if you want to be a pro gamer, to make a career out of it, what does it actually take? A lot of dedication, according to pro gamer Ryan “Big Apple Pie” Gresty.
“It takes a lot of your life up, but when you’re in a one-versus-one situation and you know what play to make, you realize all the practice has paid off,” Gresty said. He added that many gamers — or at least himself and the gamers he knows — suffer from “a lack of sleep.”
Rumay “Hafu” Wang began competitive gaming at age 14. Now 23, she evolved her gaming career from team competition, traveling around the world withFnatic, to becoming a full-time streamer on Twitch.
“Streaming is a lot more relaxing,” she said, adding that she plays up to 12 hours a day from the comfort of her home. “You can do it at your own pace, listen to your own music and be your own boss.”
Whether you’re looking to get into team competition or streaming, the following tips can help get you started.
Become a Pro Gamer in 8 Easy Steps
Easy to understand, that is. Playing for a living isn’t all fun and games. It takes time, skill and determination to win in today’s competitive circuits. If you’re up for the challenge, here’s what you need to do:
Pick your game. With a service like Xbox Live, you can practice and compete around the clock both with and against very skilled players. It’s not about randomly finding people to play against. You have to find a game you’re good at and become exceptional at it.
Once you find that game, build your reputation as both a skilled single player and a team player.
Stay motivated. Winning and money are big motivators for pro gamers; so are family and passion. Pro gamer Marcus “ShoNuff2025” Davis has been practicing the latest Call of Duty game, Advanced Warfare.
When asked why he wanted to go pro, Davis said, “First, I want to be the best so my Dad doesn’t think I’m asking for all these games and PC upgrades for nothing. Then I want to have fun doing what I already love doing.”
Practice. Study the best tactics, watch a ton of gameplay and learn how to lose. Even when you lose, you’re practicing, and practice really makes perfect. Tyler “Teepee” Polchow, who was part of the team compLexity (now Evil Geniuses), which won the Call of Duty World Championship in 2014.
Polchow
“Winning the championship was the pinnacle of my professional gaming career,” Polchow said. To get there, Polchow practiced with his team eight-plus hours a day, live-streamed the games and created other content.
“We were up against the best and had to prove we were better. The grand finals against Team EnvyUs was a quick 3-0 sweep for us, and it was in the last minutes of the third map where we secured the victory,” he said.
“A $100,000 check and the prestige of being a world champion is what all pro gamers strive for, and having that become a reality was one of the most gratifying and relieving feelings.”
Gear up. You need equipment that allows you to properly test your skills against the competition. It might be nice to have the hottest PC, but the most important thing is to choose one with the right performance that suits your lifestyle.
You can get a thin and light gaming notebook to bring to meet up with teammates or make sure practice doesn’t slow down when you travel.
A highly customizable desktop will help ensure that you have the most up-to-date hardware for your ever evolving games. As long as you have an Xbox or PlayStation, you’ll be able to compete.
Join the community. As much as pro gaming is about individual talent, it’s also about the community and being a team player. Before starting, get to know the rules of being part of a particular gaming community.
Find a team. Once you build a reputation as a serious competitor, find a team. If you’re really good, the team will probably find you. If not, try out for teams. MLG has dedicated spots to communicate with other teams and players. There are also communities where you can foster your own team.
Enter tournaments. When you get good enough to compete in singles or with a team, start entering tournaments. Test your skills in as many online and local tournaments as possible. Tournaments happen year round, so you’ll always have a place to compete. The unfortunate news is that no matter how many tournaments you win, your status as a pro gamer is truly only solidified when you win at the pro circuit level. Winning at live events brings you not only respect, but also money. Pro gaming is a legitimate job.
Get sponsored. Today’s pro gamers benefit from sponsors who provide the necessary equipment to compete. If you want to earn a living as a pro gamer, find a way to get sponsored.
“Gaming isn’t just a hobby anymore, it’s a career path and a lifestyle for some people,” Gretsy said. “The dedication and the time put into playing is more than a 9-to-5 job with overtime.”

2014 Call of Duty World Championship image courtesy of Activision.
Daylon Furlough is the author of the Day 8 New Human war book series. He is known in the gaming industry as The Velvet Voice, aka Deacon. He received the Microsoft Xbox MVP for 8 consecutive years and has a love for all things tech, nerd, geek and gaming. He hosts a variety of entertainment events in Dallas, including movie premieres, mobile phone launches, game launches and more. You can visit his website at UNSCRIPTED XBOX.


Stealthy GlassRAT Spies on Commercial Targets


A remote access Trojan used sparingly in targeted attacks has been found after living under cover for three years, undetected by most security gear.

The RAT, dubbed GlassRAT, was signed with a certificate belonging to a popular Chinese software company with hundreds of millions of users worldwide. The RAT was used to spy on Chinese nationals working in commercial outfits, and could have ties with other malware campaigns dating back to 2012.

 The malware was discovered earlier this year by researchers at RSA Security during an incident response call. The victim, as it turned out, was a Chinese national working at a large “multinational corporation,” RSA said; the victim was not in China. It’s unknown how the victim was infected, whether via a phishing campaign, drive-by download or some other means, RSA said.

“There’s not a whole lot of insight into that beside the specific activity on the multinational company’s network where there was command and control traffic from the device via command line,” said Kent Backman, the primary researcher on the investigation. “There was an actor on the other side investigating the network that the laptop was on. It seems like an intelligence-gathering tool; that’s the most likely purpose for this RAT.”

While these targets were primarily commercial for the purposes of industrial espionage, some of the command and control infrastructure used by GlassRAT was also used in previous campaigns against geopolitical targets, likely for some sort of political espionage.

“We tend to believe that because the targeting is different, going from geopolitical to commercial, that we’re probably dealing with a different division of a much larger hacking organization that showed a few of its cards with respect to command and control, Backman said.

RSA said it had to wait several months for a hit on a Yara signature it uploaded to VirusTotal and other sources before it was able to conclude that the GlassRAT infrastructure was also used to in attacks against the Philippine and Mongolian governments but with different malware, Mirage (MirageRAT), magicFire and PlugX.

“The temporal overlap window in shared infrastructure was relatively short implying a possible operational security slip by the actors behind GlassRAT if not deliberate sharing of infrastructure,” RSA wrote in a report published today.

RSA would not disclose the company whose certificate was stolen, but did say that it has subsequently been revoked. The cert was used to sign a dropper for the malware, which deletes itself after downloading the malware to the compromised machine. RSA said that the unnamed Beijing-based software company develops one app in particular that has more than 500 million users, and it’s that application’s name that the same name used by the malware in the certificate dialog box during installation.

“We know this malware was extremely effective on the large multinational corporation,” Backman said. “It was not detected for years by antivirus, and chances are had if it were more widely targeted, the chances of escaping AV would have been less.”


5 Must-Use Google Analytics Strategies to Measure SEO Success


You know what they say, “If you can’t measure it, you can’t improve it.” In Search Engine Optimization measurement is critical to success. Sure, keyword rankings are a great measure of SEO. More keywords ranking higher means more traffic, right? But, reporting solely on keywords devalues the marketer’s role and doesn’t paint the full picture of why SEO is important to the organization. Going beyond keyword rankings allows marketing teams to showcase what really matters: how organic search brings revenue and profit to the business. Thankfully, one of the best tools for measuring SEO is freely available, and probably already installed on your website – Google Analytics!
Although every business is unique and every website has different metrics that matter, this post is a universal list of 5 ways to use Google Analytics to report the success of your businesses SEO efforts.

1. How to View Only Organic Search Traffic

This one might seem obvious. I’m always surprised at how many companies see a decline in overall website traffic and immediately jump to the conclusion that the traffic loss is due to a decline in organic search traffic. Many times digging a little deeper can actually reveal that organic traffic is up while other traffic sources are down which is resulting in the overall traffic decline.
The first step in looking at Organic Search traffic over time is to open yourChannel Grouping report which can be found by clicking Acquisition > All Traffic > Channels. There you will see traffic sources segmented by channel.
Clicking on the “Organic Search” channel will give you a more detailed report which includes only organic search traffic metrics.
Click to Enlarge+
explorer chart (Infographic)
This report will be the Swiss Army Knife to your SEO reporting. From this report you can determine things such as the top landing pages for search traffic, keywords driving the most traffic, which search engines are sending the most traffic, top exit pages and much, much more.

2. How to Measure The Quality of SEO Traffic

A lot of times I hear that “quality” is subjective, so you can’t really measure it. I don’t believe this to be true and in fact, I’d say there are a lot of ways to measure the quality of any traffic source, not just search.
The most common report I use to measure an improvement or decline in the quality of search traffic is the Assisted Conversions report (Conversions > Multi-Channel Funnels > Assisted Conversions). With this report active I like to start by setting the date range to ‘Last month’ and comparing it to ‘Previous period’. What you’re left with is a month-to-month comparison of conversions directly from search, or in the event of multiple visits to the site, conversions where search played a role but is not directly attributed with the conversion (ie: the visitor found the company through search, but returned directly and converted).
Use this report to look for a decline or improvement in conversions from search traffic. If businesses notice a decline in conversions from search, yet overall search traffic is steady, it’s easy to determine that the traffic coming from search is not qualified or of a very high quality.
Likewise, if you begin focusing on a more refined set of keywords and see an improvement in conversions from search traffic, you can say your SEO traffic quality is improving.

3. Assigning Dollar Values to Organic Traffic

This is a strategy I use for businesses who are looking for a more traditional way to understand the value SEO is bringing to their business beyond improvements in traffic, visibility and conversions by assigning a dollar value to their organic traffic results. To assign a total dollar value to a sites organic traffic, I compare how much the keywords would cost if purchased in a Google AdWords campaign.
Note: For this strategy to work you will need access to a Google AdWords account, and your Analytics will need to be synced with your Search Console account.
To find a sites keyword search phrases and queries, navigate to Acquisition > Search Engine Optimization > Queries.
With this report pulled up, open your AdWords account in a new tab and clickTools > Keyword Planner. For this strategy we want to choose “Get search volume data and trends”, enter the top keywords from your Google Analytics Queries report, and click “Get search volume.” On the next screen click “Keyword Ideas.” Each keyword you’ve entered will have a Suggested Bid amount which is an estimate of what advertisers are currently paying per click for each keyword listed.
In a spreadsheet I will list all known keywords driving traffic to the website, the amount of click-throughs from each keyword, and the estimated cost-per-click. The final column in the spreadsheet is the sum of the estimated cost per click multiplied by the amount of clicks, resulting in the total organic traffic value per keyword.
This is a great strategy to visualize what kind of dollars and cents a businesses SEO strategy is saving them on traffic they would otherwise have to pay for.

4. Identifying Slow Loading Page Times

The need to optimize page load times is one item that is majorly overlooked by many SEO’s. In addition to how slow loading pages affect the user experience, page speed has become a major factor in search rankings. That’s why I always suggest that if a business is investing time and money in SEO and keyword rankings, don’t blow it by overlooking a slow loading website.
While we aren’t going to talk about how to make a website load faster, I want to look at how to identify slow loading pages and measure their impact on conversion rates.
To measure page load times on a page-by-page basis navigate to Behavior > Site Speed > Page Timings. I like to set the middle column to ‘Avg. Page Load Time’ and the right column to ‘% Exit’. I also will typically add a ‘Secondary Dimension’ of Medium, and filter down to show only organic traffic.
What this report shows us in the top most row is the average page load time site wide, and the average exit percentage (where a visitor decides to leave the site) on a page-by-page basis. It’s also fairly easy to see in this report that as our page load time surpasses our site wide average, our exit percentages begin to skyrocket.
As an SEO, what I will do is bring this report to the site developers and ask them to do everything they can to optimize page load times. Once page load times have been improved, I will run this same report and compare it to the old data to show how much additional search traffic we’ve retained, and most likely converted due to the improvement in page load times.

5. Create Your Own SEO Dashboard

Sometimes all it takes to move a client or boss from a skeptic to a believer in your work is how the data is presented. It’s easy as an internet marketer – or more specifically an SEO – to over explain ourselves, or lean on hard-to-grasp metrics. Sometimes all the client wants to see is bar graphs, pie charts and other less intimidating forms of measurement.
The best way I’ve found to present Google Analytics and SEO data is through the built in Dashboard interface. A Dashboard is essentially a series of Widgets which pull all of the individual reports into a single view which is easy to access, share, and print. The bonus to having an easily presentable PDF of SEO metrics is the fact that having this dashboard will also cut down on your time spent reviewing Analytics letting you focus on actually doing the SEO work.
If you want to skip the details and import my dashboard you can do that, otherwise click on Dashboards > + New Dashboard.
The first widget I always set up is a simple counter to measure total visits to the site from organic search. Click on “+ Add Widget”, and title it “Total Organic Visits”. For this widget I usually stick with the ‘Metric’ display. Under “Show the following metric:” select ‘Sessions’. Since we only want to see traffic from organic search we need to create a filter. Under “Filter this data:” select Only show > Medium > Exactly matching > organic.
Let’s set up one more widget. My second favorite widget measures keyword phrases sorted by the amount of sessions and goal completions resulting from the respective keyword. Let’s add a new widget like before, but this time let’s set our display as “Table”. Under “Display the following columns:”, choose Keyword > Sessions > Goal Completions. We also want to apply the same organic traffic filter as our first widget.
I like tailor these reports to the specific client, but other widgets I usually create include:
  • All Organic Visits Over Time (Timeline)
  • Top SEO Landing Pages
  • Top Organic Keywords & % of New Visits
  • Pages per Visit by Organic Keyword
  • Most Successful Keywords by Goal Completions

Turning a Challenge Into a Strength

By far, the single most challenging aspect of being an SEO is being able to effectively articulate the value you are bringing to a business. It’s easy for an SEO to show another SEO how his or her numbers are improving, but being able to quantify your work from a traffic and revenue stand point to a client or your boss is essential to earning and retaining business. If a client doesn’t understand what that check they’re writing is doing for their business, it won’t be long before they stop writing that check.
Pay attention to what metrics resonate with your client or boss and find a creative way to represent this data in your monthly SEO reports. For extra brownie points, when clients or bosses have shared access to the Analytics I always make a point to walk them through the custom dashboards showing them exactly what each widget is tracking and why it’s important to measure. Being able to educate your client on your process helps them appreciate the value you’re bringing to their business and view you as an asset to their future traffic goals.
Wednesday, November 25, 2015
Tag :

Iranian Hackers Attacked State Department From Facebook Account


Iranian Hackers Attacked State Department From Facebook Account
Iranian Hackers Attacked State Department From Facebook Account
Iranian hackers working under Iranian Government, hackers in October attack social media accounts of State Department employee. Neither the victim nor the US government has got information regarding the breach.
Hackers working for the Iranian government supposedly broke into the online networking records of a few individuals at the State Department a month ago. Also, neither the casualties nor the US government thought about it until Facebook alarmed them to the break. These interruptions are a piece of a greater cyberespionage battle, as per a report in the US blog post that refers to unknown government authorities.
It’s vague how harming or fruitful the hacking effort has been, however these assaults affirm that Iran is dynamic in the internet, and that the US government, and its workers, are badly arranged to counter or counteract such assaults. State Department representatives didn’t even notice the assaults until Facebook communicated something specific informing them they had been casualties of a cyberattack.

Iranian Hackers Attacked State Department From Facebook Account

“We trust your Facebook account and your other online records may be the objective of assaults by state-supported on-screen characters,” the caution expressed. The State Department did not answer a solicitation for input, and Facebook likewise declined to remark. In any case, a year ago, private security analysts say, Iranians started utilizing cyberattacks for reconnaissance, instead of for annihilation and interruption.
Iranian Hackers Attacked State Department From Facebook Account
Iranian Hackers Attacked State Department From Facebook Account
Starting in May 2014, scientists discovered proof that Iranian programmers were focusing on Iranian nonconformists, and later arrangement creators, senior military work force and resistance temporary workers in the United States, England and Israel, as indicated by a report by iSight Partners, a PC insight firm in Dallas.
Generally, other researchers said, the assaults were fundamental “lance phishing” endeavors, in which aggressors attempted to draw their casualties into tapping on a malevolent connection, for this situation by mimicking individuals from the news media. Iranian programmers were fruitful in more than a quarter of their endeavors.
The quantity of such assaults came to a peak in May only in front of the atomic talks in Vienna in July coming to more than 1,500 endeavors, as indicated by scientists at Checkpoint, the Israeli cybersecurity organization. Be that as it may, a source near the occurrence, who requested that talk secretly given the affectability of the matter, affirmed The New York Times report. Recently, Motherboard reported that programmers with connections to the Iranian government were included in a progression of endeavors to bargain the Gmail records of columnists and activists.
    For the last couple of years, US government authorities and private security firms alike have been cautioning that Iran has been getting more dynamic and complex in its cyberattack endeavors, in spite of the fact that there’s minimal hard confirmation of what, precisely, those endeavors involve. That crusade focused on diaspora Iranians and the activists working with them.

    Pageviews

    Followers

    Powered by Blogger.

    - Copyright © 2013 Selva Sharing -Selvasharing- Powered by Blogger - Designed by @ Access -