Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Insider pose threat for cybersecurity

By Stefan Hammond , Computerworld , 03/14/2008
  • Share/Email
  • Comment
  • Print

Bruce Schneier, founder and CTO of Counterpane, outlines the cybercrime landscape enterprises face today. He explains to Computerworld's Stefan Hammond that insiders are a problem, managed security services are a solution, and a determined crew with a chainsaw and a truck is a big problem

Computer security never seems to get better, only worse. Why?

Because security is fundamentally not a technology problem--it's a people problem. And while the technology continues to improve, increasing complexity makes the problem worse.

It's war. But it's much more interesting, and it's always pervasive.

It used to be "script-kiddies" writing goofy viruses, but it's more dangerous nowadays.

Starting about five years ago, hacking shifted from a hobbyist activity to a criminal professional activity. We see that in the structure of current viruses and worms, and in the rise of spam, identity theft and fraud. Current threats represent criminal pursuit--it is a for-profit venture. And criminals are far more dangerous than hackers.

They are also far more professional. Large-scale cybercrime is difficult. Stealing the money is only the first step. Then you have to move the money into a dummy account, probably offshore, and then convert it into something you can withdraw and use. So there's an entire financial back-end that has to be built in order to make this work.

So this crime is moving upmarket. We're seeing organized-crime gangs using identity theft and other online fraud as a way to make serious money. They're mostly coming out of Russia and eastern Europe.

Why those areas?

Because of the lack of serious law enforcement. Russia/eastern Europe is the primary breeding ground for this kind of criminal activity, Asia is second. Then sub-Saharan Africa and South America. Basically, you're looking for a place with ineffective computer crime laws, bribable police forces, and no extradition treaties. So you look for places where the police aren't going to bother. After all, if you're stealing from banks outside their country, why should they bother?

How much do you estimate is currently being stolen by cybercriminals?

We have no idea. So much isn't even reported, and there are many instances where the victims don't even know they're being attacked.

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Network World,to go. Wherever you are. Breaking news delivered to your mobile device. Select the hottest topics in networking and start receiving Network World on your mobile device today.