Recent IT Security Articles that include actual security compromises of companies, corporations and government entities. Also, in most cases,provides the breakdown in regulatory and industry security monitoring/protection requirements.
Friday, July 18, 2008
Thursday, July 17, 2008
Tuesday, July 15, 2008
Monday, July 14, 2008
Friday, July 11, 2008
Thursday, July 10, 2008
Tuesday, July 08, 2008
Monday, July 07, 2008
Wednesday, July 02, 2008
Monday, June 30, 2008
Monday, June 23, 2008
Monday, June 16, 2008
Friday, June 13, 2008
Thursday, June 12, 2008
Tuesday, June 10, 2008
Monday, June 09, 2008
Friday, June 06, 2008
Thursday, June 05, 2008
Tuesday, June 03, 2008
Monday, June 02, 2008
Friday, May 30, 2008
Tuesday, May 27, 2008
Wednesday, May 21, 2008
Tuesday, May 20, 2008
Monday, May 19, 2008
Protecting data from danger
Pittsburgh Business Times - by Kim Lyons
Joe Wojcik CERT Insider Threat Team technical leader Dawn Cappelli says data dangers are everywhere, and insider threats from company employees are becoming increasingly common. View Larger |
Dawn Cappelli isn't that scary.
But listen to her talk about her job as head of the Insider Threat Team at the Computer Emergency Response Team, part of the Software Engineering Institute at Carnegie Mellon University, and she becomes downright terrifying.
"I'm so paranoid," Cappelli said. "I try to tell people that their information isn't safe, because so many people have access to it."
Gone are the days when a company's biggest information concern was whether employees were downloading the wrong e-mail attachments. Whether it's big department stores unable to protect customers' credit card information, or smaller firms losing track of who has access to proprietary information, the threats to companies' sensitive data are constant and ever-changing.
And the long-term effects of a data breach can have an impact on a company well after the issue has been resolved, whether it's a loss of customers, or damage to the company's reputation.
Bill Shore, supervisor of the FBI's Computer Crimes Squad in Pittsburgh, said the days of hackers seeking fame and glory -- think of the "iloveyou" virus of 2000 -- are mostly over.
"Now, they try to keep under the radar," Shore said. "They are much more profit-motivated. They're trying to find ways to get access to money."
STEALING FROM THE INSIDE
Today, more threats to companies' data come from within, Cappelli said, as some employees deliberately take sensitive information.
Many are seeking personal gain from the sale of company or customer information. In this instance, the typical insider is in a fairly low-level position, the average age is 33 and offenders come from both genders. These insiders don't have to be particularly technical, but most are relatively low paid, Cappelli said. Such insiders are sometimes approached by someone from outside the company to steal the sensitive information, she said.
Another problem is industrial espionage, where employees steals trade secrets, often when they're about to start their own company, Cappelli said. In these cases of theft for personal gain, about 71 percent of them are very technical people, who have access to new strategies or projects being developed. And, in her experience, they're male, with an average age of about 37.
A large part of the problem is the attitude of upper-level management, Cappelli said.
"This isn't something that can be just handed off to the IT department," she said. "It's difficult to watch all your employees all the time, but companies need to recognize when people are acting suspiciously."
BREAKING AND ENTERING
Inside jobs are far from the only thing that business owners have to worry about when trying to keep critical information safe.
Identity theft is huge, and not just for individuals, Shore said. He's seen phishing attempts -- where hackers try to get users to divulge sensitive information like bank account numbers -- targeted at company CFOs. Such phishing scams can potentially drain millions of dollars from a company's coffers.
Even worse, he said, are malicious programs that record keystrokes -- all the program has to do is watch for activity on a bank account Web site, and it records account numbers and password information.
Savvy companies recognize the potential threats to their customer information and other sensitive data.
John McClelland, president of Strip District-based online produce supplier Good Apples LLC, said since 90 percent of his company's business is conducted on the Internet, he protects customers' credit card information by not storing any of it. Every time a customer places an order, they must re-enter their credit card number.
"Yes, it makes it a little less convenient for customers, but we don't have the amount of money we would need to invest in security to protect that information," McClelland said. "It would be irresponsible for us to store it."
Bruce Freshwater, CEO of Robinson-based Sierra w/o Wires Inc., an IT services company, said unfortunately many companies don't want to invest in protecting their critical data until after they've had a breach.
"Ninety-five percent of the time, they don't want to expend any money until after the data has been compromised, and they've taken a $100,000 loss," Freshwater said.
Sierra's own security includes an IPS, or intrusion protection system, at its network perimeters. It guards against the kinds of internal threats that Cappelli described by assigning controls based on access requirements; the sales team can't access IT information, for instance.
FUTURE THREATS HARD TO PREDICT
James Joshi, an assistant professor at the school of information sciences at the University of Pittsburgh, said he tries to avoid predicting the future.
"But I think -- or rather, fear -- more sophisticated, coordinated multi-attacks may be the next thing that the hackers will come up with," he said. "There is already significant issues with botnets indicating this. And in most cases, organizations and systems are not that well-prepared against such cyber events."
Botnets are programs that run automatically on "zombie" computers -- a machine that's been infected with a Trojan horse or other virus or worm -- and are controlled remotely, by someone usually up to no good.
Shore said the biggest threat he sees on the horizon is the increased use in peer-to-peer, or file sharing, networks. And with economic espionage becoming more and more lucrative, Shore said, ID theft is likely to become more prevalent for both individuals and companies.
Cappelli's colleague at CERT, Nick Ianelli, specializes in malware trends and analyzing future threats. He said the potential for data compromise via instant messenger programs is becoming bigger and bigger. Social networking sites are also an area where user information is highly vulnerable, he said.
And, Ianelli said there's also a lot of malicious code that works on cell phones. Since different cell phone manufacturers use different operating systems, it's hard to create one threat that works in the vast majority of devices.
"But once that gets on a machine, it can compromise all the data on there," he said. "Anytime you plug in your phone, you provide access to it."
klyons@bizjournals.com (412) 208-3827
All contents of this site © American City Business Journals Inc. All rights reserved.
Friday, May 16, 2008
Thursday, May 15, 2008
Tuesday, May 13, 2008
Monday, May 12, 2008
Tuesday, May 06, 2008
Monday, May 05, 2008
Thursday, May 01, 2008
Wednesday, April 30, 2008
Tuesday, April 29, 2008
Monday, April 28, 2008
Sunday, April 27, 2008
Friday, April 25, 2008
Tuesday, April 22, 2008
Thursday, April 17, 2008
Wednesday, April 16, 2008
Tuesday, April 15, 2008
Monday, April 14, 2008
Thursday, April 10, 2008
Tuesday, April 08, 2008
Monday, April 07, 2008
Saturday, April 05, 2008
Friday, April 04, 2008
Wednesday, April 02, 2008
Tuesday, April 01, 2008
Monday, March 31, 2008
Friday, March 28, 2008
Thursday, March 27, 2008
Monday, March 24, 2008
Friday, March 21, 2008
Wednesday, March 19, 2008
Tuesday, March 18, 2008
Monday, March 17, 2008
Friday, March 14, 2008
Thursday, March 13, 2008
Wednesday, March 12, 2008
Tuesday, March 11, 2008
Thursday, February 28, 2008
Friday, February 22, 2008
Wednesday, February 20, 2008
Monday, February 18, 2008
Friday, February 15, 2008
Wednesday, February 13, 2008
Monday, February 11, 2008
Wednesday, February 06, 2008
Friday, February 01, 2008
Thursday, January 31, 2008
Wednesday, January 30, 2008
Tuesday, January 29, 2008
Friday, January 25, 2008
Wednesday, January 23, 2008
Tuesday, January 22, 2008
Wednesday, January 16, 2008
Tuesday, January 15, 2008
Monday, January 14, 2008
Friday, January 11, 2008
Wednesday, January 09, 2008
Tuesday, January 08, 2008
Monday, January 07, 2008
Thursday, January 03, 2008
Wednesday, January 02, 2008
Tuesday, December 18, 2007
Thursday, December 13, 2007
Wednesday, December 12, 2007
Tuesday, December 11, 2007
AdultFriendFinder.com settles with FTC - SC Magazine US
Thursday, December 06, 2007
Tuesday, December 04, 2007
Friday, November 30, 2007
Thursday, November 29, 2007
Tuesday, November 27, 2007
Monday, November 26, 2007
Tuesday, November 20, 2007
Monday, November 19, 2007
Thursday, November 15, 2007
Wednesday, November 14, 2007
Tuesday, November 13, 2007
Monday, November 12, 2007
Thursday, November 08, 2007
Encrypted E-Mail Company Hushmail Spills to Feds
Wednesday, November 07, 2007
Tuesday, November 06, 2007
Monday, November 05, 2007
Friday, November 02, 2007
Thursday, November 01, 2007
Tuesday, October 30, 2007
Tuesday, October 23, 2007
Monday, October 22, 2007
Friday, October 19, 2007
Thursday, October 18, 2007
Tuesday, October 16, 2007
Thursday, October 11, 2007
Wednesday, October 10, 2007
Tuesday, October 09, 2007
Monday, October 08, 2007
Friday, October 05, 2007
Wednesday, October 03, 2007
Tuesday, October 02, 2007
Monday, October 01, 2007
Thursday, September 27, 2007
Monday, September 24, 2007
Friday, September 21, 2007
Thursday, September 20, 2007
Tuesday, September 18, 2007
Monday, September 17, 2007
Thursday, September 13, 2007
Monday, September 10, 2007
Friday, September 07, 2007
Thursday, September 06, 2007
Tuesday, September 04, 2007
Wednesday, August 29, 2007
Monday, August 27, 2007
Thursday, August 23, 2007
Wednesday, August 22, 2007
Tuesday, August 21, 2007
Friday, August 17, 2007
Thursday, August 16, 2007
Wednesday, August 15, 2007
Tuesday, August 14, 2007
Tuesday, August 07, 2007
Friday, August 03, 2007
Thursday, August 02, 2007
Wednesday, August 01, 2007
Tuesday, July 31, 2007
Monday, July 30, 2007
Friday, July 27, 2007
Thursday, July 26, 2007
Wednesday, July 25, 2007
Tuesday, July 24, 2007
Monday, July 23, 2007
Thursday, July 19, 2007
Wednesday, July 18, 2007
Tuesday, July 17, 2007
Monday, July 16, 2007
Cybersecurity realities hit financial firms - Austin Business Journal:
Austin Business Journal - July 13, 2007
by Ed Amoroso
Contributing Writer
Like it or not, we are reliant on computer and network systems for our business and personal financial needs. We enjoy greater access to near real-time financial data than ever before.
That's one reason I cringe when someone from the banking and finance industry claims to have never been hacked. I've seen plenty of overly confident information technology types wish they had taken a closer look. One reason attacks are fairly widespread is that when PCs are connected to networks, they are immediately exposed to all sorts of security threats. Moreover, the most common security initiatives, such as firewalls, can be penetrated or bypassed quite easily in many environments.
Disclosed secrets
The payment card industry has been especially challenged by disclosure of personal information. Unfortunately, very little progress has been made in prevention of disclosure threats on computers. While encryption works well for information in transit, it can be compromised when information is stored.
Theft
Stopping online fraud can be especially challenging because the identity and location of end points can be tough to accurately determine. The most common method of identity theft involves phishing scams in which individuals are convinced to supply personal information by an official-looking email. One promising technique to prevent phishing provides stronger forms of authentication through the use of tokens that randomly generate a different numeric password every minute.
Destroying and deleting assets
In a nationwide survey of 1,000 U.S.-based IT executives conducted by AT&T, 74 percent rated viruses and worms among the top three threats. Even so, most organizations rarely back up anything but the most critical information, which leaves the vast majority of their information at risk. To protect against PCs being corrupted, files being infected or system attributes being changed, it is essential to establish standards that ensure periodic backups. Using systems that enable audit trails and control access to individual devices and the network are also strongly recommended.
Denial of service
Denial of service in cybersecurity involves a malicious intruder intentionally blocking a computer of network service from its authorized users. To be frank, this is a capacity issue. If a system can only handle so much capacity, then attackers can simply initiate malicious activity that will exceed that capacity. In the financial services industry, the good news is that considerable emphasis has been directed toward reducing security risks. Massive investments have been made to reduce fraud and protect networks from hackers, criminals and cyber terrorists. Ultimately, there is no substitute for software developed with security in mind, improved system administration and reduced system complexity.
Ed Amoroso is senior vice president and chief security officer for AT&T and the author of "Cyber Security."
Contact the Editor
All contents of this article © American City Business Journals Inc. All rights reserved.