Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts

Thursday, March 18, 2010

Hacker Series (Part 4)

Hacker Series (Part 4)

Every new innovation in networking speed and usability comes with an equivalent increase in risk, so companies must keep up with the onslaught of threats present throughout the web. The companies keep up by implementing a patch, or "quick fix" to the programming threat that exposes the Internet security of the company. Over the last 30 years there has been a rise in the use of firewalls, antivirus software, and spam filters as IT managers fight to protect the technology but it is a battle with a new front daily. This makes it critical for IT managers to be continually educated about the advances in threat and defense through journals, magazines and conferences.


A recent article in Business Wire Magazine (2009) indicated another threat to business. Hackers are able to steal contact lists and classified documents from smart phones like Blackberries. These phones have enhanced features, allow peers to communicate, allow Web browsing and have multiple voice and data interfaces. The article went on to say that the variety of interfaces make exploitation easier. For example: “Short Message Service (SMS) feature, available on just about any smartphone device, gives hackers a way to: Inject viruses ,steal user data, e-mails, contacts and data files, clone devices and create DOS attacks “. New software is being developed by a variety of companies to help the IT managers deal with this new arena of threat.

The additional requirement of security on the Web has created a number of regulations that companies must put into practice such as the Sarbanes-Oxley Act, but there are several additional regulations that exist to promote security over the web. For example, the Health Insurance Portability and Accountability Act (HIPAA) were enacted in 1996 in part to protect healthcare information on the web. Section 501 of the Gramm-Leach-Bliley Act (GLBA) requires financial services firms to implement and enforce a written "information security program" to protect non-public customer data. Sarbanes-Oxley (SOX) requires that companies implement an internal control framework which includes implementing appropriate information technology tools and processes to ensure internal control (McNamara, 2005).

IT managers must lobby companies to set aside more money and resources to implement controls in order to comply with these regulations, or their employees could be legally responsible for fines or imprisonment. Legislation and regulations governing HIPAA, and SOX include criminal penalties: up to 10 years in prison with HIPAA for "obtaining or disclosing protected health information", and 10 to 20 years with SOX for "destruction, alteration or falsification of records" (McNamara, 2005). The IT manager would certainly be in line for any discipline if these regulations were not complied with so they have the right and responsibility to be informed.

Wednesday, March 17, 2010

Hacker Series (Part 3)

The shift toward doing more over the Web, a practice known as "cloud computing", means that mistakes employees make in their private lives can do serious damage to their employers, because a single e-mail account can tie the two worlds together. Stealing the password for an individual’s Gmail account, for example, not only gives the hacker access to that persons personal e-mail, but also to any other Google applications they might use for work, like those used to create spreadsheets or presentations.


Email systems are a serious source of ingress for hackers. False e-mails in the name of a legitimate company or institution are sent to acquire sensitive personal information, such as usernames, passwords, and credit card numbers and often come to company email addresses. Phishing is cost effective for hackers and sometimes yields results that damage more than just the individual. An IT manager should block any emails from a questionable source and educate their users to delete any spam that makes it through the filters. It has been reported that 89.7 percent of all business email is spam. Trojans can be used to assume control over the infected PC and can cause damage such as a Key Logging application. Key Logging refers to the process of capturing and recording user keyboard strokes to obtain passwords or other encryption keys. Given the sheer volume of employees in large corporations, even one or two password or encryption captures could bring about great damage and loss.

The biggest threat to databases is Web applications according to experts and the business logic vulnerabilities within them.

“Close ties with Web applications can make databases vulnerable to SQL injection attacks, whereby attackers input strings of SQL code into weak Web applications fields. They can then raid the database linked to a specific Web application, and also use the link between the Web application and the database to launch more expansive attacks on entire database servers. According to IBM's ISS X-Force security research unit, SQL injection flaws last year were the Internet's most commonly exploited Web application vulnerability, growing by 134% over 2007” (Chichiwski, 2009)

In reality a large percentage of the security threats potentially go after the database. According to a Verizon report, database breaches accounted for 75% of all records reported breached. Many database security vulnerabilities are caused by simple lapses in security. In a 2008 poll, the Independent Oracle Users Group found that 26% of organizations take more than six months to install security patches on Oracle databases; 11% have never patched them.. Companies often make mistakes that leave databases vulnerable, such as leaving test databases on production servers or linking sensitive data to easily hacked Web-facing applications.

Tuesday, March 16, 2010

Hacker Series (part 2)

A final but perhaps unworkable solution to many problems is to ban the use of social networking sites from a company computer. IT security and data protection firm Sophos has published new research into the first six months of cybercrime in 2009. They reported existing and emerging security trends and identified that criminals have increased the focus of attacks on social networking sites. Several major recent attacks have been made because of information that was taken from an individual’s social networking site like Facebook or Twitter. IT teams are worried that employees share too much personal information via social networking sites even on their personal computers, putting their corporate infrastructure - and the sensitive data - at risk. The findings also indicate that a quarter of organizations have been exposed to spam, phishing or malware attacks via sites such as Twitter, Facebook, LinkedIn and MySpace. Internet security is a critical factor in an organization's performance, impacting everything from business continuity to cost management. The challenges with Internet security and privacy include hackers, worms, Spyware, firewalls, spam filters, object request brokers, authentication of users, encryption of data, security architecture, limits on protection from threats, and government regulations.


The Internet allows a company to potentially expand its customer base to any Internet enabled area of the world, but outside threats such as worms and viruses could potentially corrupt the data being transmitted to customers. Also, employees are able to conduct business from anywhere in the world, but unauthorized users can "hack" into confidential company data being transmitted over the web to or from the employee. When a corporation begins exchanging any type of business transaction over the Internet, the Internet becomes part of the "corporate computer network". Access is now available not only to the customers or employees, but potentially to anyone else on the Internet, so the scope of concern for security expands significantly (Bunton, 2005). The techniques used by the attackers highlight the dangers of a broader trend toward storing more data online, instead of on computers under your control.

Saturday, March 13, 2010

Hacker Series Part One

Hackers



“Cyber attacks pose the greatest threat to the United States after nuclear war and weapons of mass destruction -- and are increasingly hard to prevent” said Shawn Henry, assistant director of the FBI's cyber division. Of the six billion dollars that Microsoft spends annually on research and development, approximately one-third, or two billion dollars, is directly spent on security efforts (Talbot, 2005). IT managers are on the front line of a guerilla war when it comes to protecting computer technology from hackers. It is a continual game of one-upsmanship as one vulnerability closes another seems to appear. There are, however, a number of basic things that an IT manager can do to protect her company and it all starts with vigilance.


McNurlin et al 2006 indicate that security has five pillars. They are: authentication, identification, privacy, integrity and non-repudiation. Authentication means verifying someone’s authenticity: They do this by supplying information such as a password, answer to a question or the number from a digital token. It can also be done using biometrics. Current best practice suggests using two of the three methods, which is called two-factor authentication. For example, in order to get into my company computer I must enter passwords and the number from a token. However, that only gets me to a certain point. I must be identified to go into various areas of the company system. I am not authorized to go into certain areas and a notification will appear on my screen if I attempt to access them. Data privacy and integrity also have to be preserved. Not all data is for all eyes. Some is read-only format so that it may not be changed. Data is also encrypted when sent so that it cannot be intercepted and read from the Internet. The final method is non-repudiation which means that the actual sender and the actual receiver are authenticated and that fact is not deniable. All of this security has no purpose if it is not used and thus it must begin with the user.

Internal users should be included in the defense of the company through timely and repeated education. Everyone who has access to company computer systems should be taught and reminded that they are very important to the security and well-being of the company. While every company should have the very latest protection software and its current update, users should be reminded to update it frequently or better yet, it should be automatically updated. Taking human memory out of the equation as much as possible is wise. In addition “cookies” should be cleared frequently.

Users should be instructed on how to choose strong passwords. IT managers need to remind people to change their passwords frequently. It is natural and comfortable to choose a password that is easy to remember. That normally includes dates of important events in the individual’s life or other obvious words. Unfortunately, strong passwords are ones that have no mnemonic significance. Passwords that are strong are often hard to remember so the temptation is then to write them down somewhere where someone else might find them. Even then, when the user takes these precautions, hackers can use brute force for uncovering passwords if all else fails. Users need to be warned not to answer a phone call from anyone who says that they are from IT and that they need their password to perform maintenance. More and more biometric entry to computerized systems appears to be the way to go.

Friday, March 12, 2010

Problog to a Series of Postings on Hackers

Problog (Prologue) to the Hacker Series


In future blogs I will discuss the ongoing challenges that a vigilant IT manager must face to keep a company system safe and one blog will be on the psychoological profle of hackers. The five pillars of security are: authentication, identification, privacy, integrity and non-repudiation. The IT manager must educate the users as to their important role in keeping a system safe. While an IT manager should implement a two-factor authentication process, users must choose strong passwords, avoid social networking sites, exercise special care with email, never forwarding spam or opening messages from unknown senders and regularly update their anti-virus software. These policies must be clear and reiterated often by IT staff. IT managers must also ensure that databases are kept secure through prompt patching, The blog will also mention government regulations that have sought to keep Internet data safe yet have added stress to the IT role. It also mentioned the surprising security that a flash drive can offer and the surprising threat of a humble laser. Finally, it is recommended that IT managers be allowed time to keep up to date by education, reading, seminars, and conferences such as the Black Hat events. Overall, the job of security is a never ending battle of wits in which vigilance and persistence must be practiced.