Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

The case of the tampered USBs

Insider Threat By Faizel Lakhani , Network World , 05/12/2008
  • Share/Email
  • Tweet This
  • Comment
  • Print

I was just at a conference and heard that despite all the press and focus on hacking and viruses, there is a 72 percent likelihood that the next successful attack will come from an insider (according to statistics from ISCSA Labs). Why isn't this number going down?

For years, organizations have focused on the evil outsiders that were behind attacks on their networks. Firewalls, IDS, IPS technologies have come to the rescue and have resulted in impregnable walls protecting organization networks. Now with strong walls, the challenge is ensuring the trusted insiders don't walk out with the king's crown.

Recently, I heard a story of a black-hat firm trying to gain access to a pharmaceutical company's secrets. They put 4Gb USB sticks (properly marked and in manufacturers' packaging) all over the parking lot. Employees picked up the sticks and some went straight to their computers and inserted them to see if they worked. Unknown to the employees, the USB had a boot program that installed a piece of software. The software made a copy of all outgoing mail. The duplicated e-mail was then being sent to the black hat servers, right through the firewall the company had.

Another example is a client where I went to review the finding of a risk assessment we had done. We had left our appliances deployed for one week and went back and created a report for presentation. The report contained incidents of data leakages. At the executive presentation we highlighted a highly secret spreadsheet that was sent to a number of consultants that should not have seen it. In the meeting the CIO challenged the findings and stated that it was impossible for someone to have sent that spreadsheet and he wanted the details of who sent it. We went to our appliance and found that it was sent by the CIO, except it was a tab in a larger spreadsheet. Organizations face data leakage not only from malicious activities but also from accidental disclosure.

So how does a company keep up? Can anyone know all the ways in which data can leave a company? Can they know who should see what? The challenge now exists in using an organization's traffic to determine what is normal, to investigate unusual activities or to validate the rules they have in place. This is the future of information security, surprisingly using an organizations own historical traffic to learn about what to protect.

  • Share/Email
  • Tweet This
  • Comment
  • Print
Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed