Pages

Monday, July 14, 2008

Monday, May 19, 2008

Techworld.com - Computers at risk from Crazy Raspberry ants

Researchers find new ways to steal data | InfoWorld | News | 2008-05-19 | By Robert McMillan, IDG News Service

Protecting data from danger

As employees, hackers become more sophisticated, sensitive information is no longer safe

Pittsburgh Business Times - by Kim Lyons

Joe Wojcik
CERT Insider Threat Team technical leader Dawn Cappelli says data dangers are everywhere, and insider threats from company employees are becoming increasingly common.
View Larger

Dawn Cappelli isn't that scary.

But listen to her talk about her job as head of the Insider Threat Team at the Computer Emergency Response Team, part of the Software Engineering Institute at Carnegie Mellon University, and she becomes downright terrifying.

"I'm so paranoid," Cappelli said. "I try to tell people that their information isn't safe, because so many people have access to it."

Gone are the days when a company's biggest information concern was whether employees were downloading the wrong e-mail attachments. Whether it's big department stores unable to protect customers' credit card information, or smaller firms losing track of who has access to proprietary information, the threats to companies' sensitive data are constant and ever-changing.

And the long-term effects of a data breach can have an impact on a company well after the issue has been resolved, whether it's a loss of customers, or damage to the company's reputation.

Bill Shore, supervisor of the FBI's Computer Crimes Squad in Pittsburgh, said the days of hackers seeking fame and glory -- think of the "iloveyou" virus of 2000 -- are mostly over.

"Now, they try to keep under the radar," Shore said. "They are much more profit-motivated. They're trying to find ways to get access to money."

STEALING FROM THE INSIDE

Today, more threats to companies' data come from within, Cappelli said, as some employees deliberately take sensitive information.

Many are seeking personal gain from the sale of company or customer information. In this instance, the typical insider is in a fairly low-level position, the average age is 33 and offenders come from both genders. These insiders don't have to be particularly technical, but most are relatively low paid, Cappelli said. Such insiders are sometimes approached by someone from outside the company to steal the sensitive information, she said.

Another problem is industrial espionage, where employees steals trade secrets, often when they're about to start their own company, Cappelli said. In these cases of theft for personal gain, about 71 percent of them are very technical people, who have access to new strategies or projects being developed. And, in her experience, they're male, with an average age of about 37.

A large part of the problem is the attitude of upper-level management, Cappelli said.

"This isn't something that can be just handed off to the IT department," she said. "It's difficult to watch all your employees all the time, but companies need to recognize when people are acting suspiciously."

BREAKING AND ENTERING

Inside jobs are far from the only thing that business owners have to worry about when trying to keep critical information safe.

Identity theft is huge, and not just for individuals, Shore said. He's seen phishing attempts -- where hackers try to get users to divulge sensitive information like bank account numbers -- targeted at company CFOs. Such phishing scams can potentially drain millions of dollars from a company's coffers.

Even worse, he said, are malicious programs that record keystrokes -- all the program has to do is watch for activity on a bank account Web site, and it records account numbers and password information.

Savvy companies recognize the potential threats to their customer information and other sensitive data.

John McClelland, president of Strip District-based online produce supplier Good Apples LLC, said since 90 percent of his company's business is conducted on the Internet, he protects customers' credit card information by not storing any of it. Every time a customer places an order, they must re-enter their credit card number.

"Yes, it makes it a little less convenient for customers, but we don't have the amount of money we would need to invest in security to protect that information," McClelland said. "It would be irresponsible for us to store it."

Bruce Freshwater, CEO of Robinson-based Sierra w/o Wires Inc., an IT services company, said unfortunately many companies don't want to invest in protecting their critical data until after they've had a breach.

"Ninety-five percent of the time, they don't want to expend any money until after the data has been compromised, and they've taken a $100,000 loss," Freshwater said.

Sierra's own security includes an IPS, or intrusion protection system, at its network perimeters. It guards against the kinds of internal threats that Cappelli described by assigning controls based on access requirements; the sales team can't access IT information, for instance.

FUTURE THREATS HARD TO PREDICT

James Joshi, an assistant professor at the school of information sciences at the University of Pittsburgh, said he tries to avoid predicting the future.

"But I think -- or rather, fear -- more sophisticated, coordinated multi-attacks may be the next thing that the hackers will come up with," he said. "There is already significant issues with botnets indicating this. And in most cases, organizations and systems are not that well-prepared against such cyber events."

Botnets are programs that run automatically on "zombie" computers -- a machine that's been infected with a Trojan horse or other virus or worm -- and are controlled remotely, by someone usually up to no good.

Shore said the biggest threat he sees on the horizon is the increased use in peer-to-peer, or file sharing, networks. And with economic espionage becoming more and more lucrative, Shore said, ID theft is likely to become more prevalent for both individuals and companies.

Cappelli's colleague at CERT, Nick Ianelli, specializes in malware trends and analyzing future threats. He said the potential for data compromise via instant messenger programs is becoming bigger and bigger. Social networking sites are also an area where user information is highly vulnerable, he said.

And, Ianelli said there's also a lot of malicious code that works on cell phones. Since different cell phone manufacturers use different operating systems, it's hard to create one threat that works in the vast majority of devices.

"But once that gets on a machine, it can compromise all the data on there," he said. "Anytime you plug in your phone, you provide access to it."


klyons@bizjournals.com (412) 208-3827


All contents of this site © American City Business Journals Inc. All rights reserved.

Tuesday, April 29, 2008

Banks Told to Prep for New International ACH Rules - Bank Systems & Technology

HP ships USB sticks with malware - CNET News.com

Microsoft: Massive site attacks not our fault

Techworld.com - Xerox's PARC boffins show off new inventions

Techworld.com - Bank owns up to laptop disaster

PCI council clarifies impending application rule - SC Magazine US

Another Apple QuickTime bug reported - SC Magazine US

Skype users land in anti-malware net - SC Magazine US

Hacker denies using tool to break into Dish Network security - SC Magazine US

Massive hacker attack continues - SC Magazine US

Another college exposure, now in Colorado - SC Magazine US

"Highly critical" flaw in WordPress - SC Magazine US

Sunday, April 27, 2008

Thursday, April 17, 2008

Tuesday, April 08, 2008

Monday, April 07, 2008

PA-DSS secures payment applications

PA-DSS secures payment applications

Laptop theft easily preventable while on the road

un-excogitate.org � Blog Archive � Old School Biometrics Hacking And Enterprise Physical Access Control

2600: The Hacker Quarterly

The IT Security Guy: Spring 2600 Hits Newstands

IT 'Big Brothers' trying to keep internal users under control

Security chiefs urged to embrace risk

IT security budgets on the rise - vnunet.com

Remote workers ignoring security - vnunet.com

M&S rapped for Data Protection breach - vnunet.com

Watchdog slams Skipton over data loss - vnunet.com

Police lose yet more data - vnunet.com

HSBC loses 370,000 customer details - vnunet.com

Tuesday, March 18, 2008

Thursday, March 13, 2008

Wednesday, February 13, 2008

Wednesday, February 06, 2008

Tuesday, January 29, 2008

New data security breaches come in fours

Florida woman accused of deleting $2.5 million in data - SC Magazine US

Security tokens coming for eBay's PayPal customers - SC Magazine US

PayPal to acquire Fraud Sciences for $169 million - SC Magazine US

Western Union spam downloads keylogger - SC Magazine US

Super Bowl blitz begins: Bogus game sites with malware popping up - SC Magazine US

US

Security lessons from the top | InfoWorld | News | 2008-01-28 | By Matt Hines

Were People or Technology to Blame for Multibillion Dollar Societe General Fraud?

Security efforts hindered by untrained users

Metasploit attack app gets update

ChoicePoint to pay $10M to settle last breach-related lawsuit

Tuesday, January 22, 2008

Tuesday, December 11, 2007

Skype apologises for forgetting 'critical' patch News - PC Advisor

Techworld.com - Security concerns cloud virtualisation deployments

Techworld.com - Data put at risk by app testing naivety

Techworld.com - Coverity tool analyses application crashes

Techworld.com - Internet poisoned by open DNS servers

Fiserv Completes Acquisition of CheckFree - Bank Systems & Technology

Cisco warns of flaws in Security Agent for Windows, CiscoWorks Server - SC Magazine US

AdultFriendFinder.com settles with FTC - SC Magazine US

This summary is not available. Please click here to view the post.

Gartner: Victims of online phishing up nearly 40 percent in 2007 - SC Magazine US

Attackers hack into Oak Ridge National Laboratory - SC Magazine US

Monday, November 19, 2007

Wednesday, November 14, 2007

Monday, November 05, 2007

Wednesday, October 03, 2007

Thursday, August 23, 2007

Thursday, August 02, 2007

Monday, July 23, 2007

Tuesday, July 17, 2007

Oracle to release 46 security fixes - IT Security News - SC Magazine US

Computer security breach puts some records at risk

Unauthorized file-sharing software leads to Pfizer employees’ data exposure

Company Says Worker Stole, Sold Data - washingtonpost.com

Statement about stolen computer back-up tapes

Hackers steal data from PCs

HACKER ATTACK $HOCK

Sensitive data loss soars

University-owned laptop with student data stolen - Minnesota Daily

Confidential data revealed on Encinitas' Web site - North County Times - Coastal -

MSD worker fired in security breach

Monday, July 16, 2007

Cybersecurity realities hit financial firms - Austin Business Journal:

Cybersecurity realities hit financial firms
Austin Business Journal - July 13, 2007
by Ed Amoroso
Contributing Writer

Like it or not, we are reliant on computer and network systems for our business and personal financial needs. We enjoy greater access to near real-time financial data than ever before.
That's one reason I cringe when someone from the banking and finance industry claims to have never been hacked. I've seen plenty of overly confident information technology types wish they had taken a closer look. One reason attacks are fairly widespread is that when PCs are connected to networks, they are immediately exposed to all sorts of security threats. Moreover, the most common security initiatives, such as firewalls, can be penetrated or bypassed quite easily in many environments.

Disclosed secrets
The payment card industry has been especially challenged by disclosure of personal information. Unfortunately, very little progress has been made in prevention of disclosure threats on computers. While encryption works well for information in transit, it can be compromised when information is stored.

Theft
Stopping online fraud can be especially challenging because the identity and location of end points can be tough to accurately determine. The most common method of identity theft involves phishing scams in which individuals are convinced to supply personal information by an official-looking email. One promising technique to prevent phishing provides stronger forms of authentication through the use of tokens that randomly generate a different numeric password every minute.

Destroying and deleting assets
In a nationwide survey of 1,000 U.S.-based IT executives conducted by AT&T, 74 percent rated viruses and worms among the top three threats. Even so, most organizations rarely back up anything but the most critical information, which leaves the vast majority of their information at risk. To protect against PCs being corrupted, files being infected or system attributes being changed, it is essential to establish standards that ensure periodic backups. Using systems that enable audit trails and control access to individual devices and the network are also strongly recommended.

Denial of service
Denial of service in cybersecurity involves a malicious intruder intentionally blocking a computer of network service from its authorized users. To be frank, this is a capacity issue. If a system can only handle so much capacity, then attackers can simply initiate malicious activity that will exceed that capacity. In the financial services industry, the good news is that considerable emphasis has been directed toward reducing security risks. Massive investments have been made to reduce fraud and protect networks from hackers, criminals and cyber terrorists. Ultimately, there is no substitute for software developed with security in mind, improved system administration and reduced system complexity.

Ed Amoroso is senior vice president and chief security officer for AT&T and the author of "Cyber Security."
Contact the Editor
All contents of this article © American City Business Journals Inc. All rights reserved.

Monday, July 09, 2007

Financial systems 'riddled with security holes'

Talking Trojan says 'bye bye' to victims' data

Fraudsters use charities to test credit cards | InfoWorld | News | 2007-07-06 | By Robert McMillan, IDG News Service

PCI Data Security Standard compliance: Three steps to success

Microsoft Security Intelligence Report Fact Sheet

The Microsoft Security Intelligence Report provides customers and partners with a comprehensive understanding of the types of threats Windows customers face today so they can take appropriate action to help ensure they are better protected.