Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

Verizon data breach report, Part 3: Breach size and source

A closer look at breach sources
Security Strategies Alert By M. E. Kabay, Network World
July 08, 2008 12:07 AM ET
Sign up for this newsletter now!

Mich Kabay takes a high-level view of security issues and provides resources to help safeguard your corporate and personal security.

  • Share/Email
  • Tweet This
  • Comment
  • Print

In my two most recent columns (Part 1 and Part 2), I've been looking at the Verizon Business RISK Team's valuable analysis of four years of data on security breaches among their clients entitled "2008 Data Breach Investigations Report." Today I'll look at the research findings concerning breach size and source.

The most interesting aspect of the data is that “The median size (as measured in the number of compromised records) for an insider breach exceeded that of an outsider by more than 10 to one. Likewise, incidents involving partners tend to be substantially larger than those caused by external sources.”

I was pleased to see the authors using the median, not the mean, of the number of records compromised; most of the reports published in our field erroneously use means (arithmetic averages) even though the variables have drastically skewed (asymmetric) frequency distributions that make those averages much less useful than for symmetric distributions. 

When the authors corrected for the number of cases involving external sources, internal sources, and partners, the numbers of records likely to be involved in a breach showed that “partners represent the greatest risk for data compromise, followed closely by insiders.” These observations support “the principle that privileged parties are able to do more damage to the organization than outsiders.”

Using as much information as they could bring together on the IP addresses of external attacks, the Verizon team found that the geographic distribution of attack origins looked like this (some of these numbers are not shown in the report but were supplied by author Wade Baker for this article):

• Europe-East: 24%
• Americas-North: 23%
• Asia-South/Southeast: 14%
• Asia-East: 12%
• Asia-North/Central (incl. Russia): 9%
• Europe-West/South: 9%
• Middle East: 5%
• Americas-South: 3%
• Africa: 1%
• Europe-North (Scandinavia): 0%
• Oceania (Austrialia/NZ): 0%
• Americas-Central: 0%

So, more than 80% of the estimated attack-sources are from Eastern Europe, North America, and Asia. These results surprised me, since I have fallen into the habit of thinking of China as the No. 1 source of threats to information security today; I have to correct my impressions and be more careful in my teaching, lecturing and writing.

On the insider front, the analysts found that half the insider attacks involved IT administrators, and about 41% involved other non-executive employees. These results are consistent with the long-held view that privileged insiders must be selected with care and consistently monitored as part of any effective security program.

Many breaches in the data set involved breaches mediated through weaknesses in partner systems:

“Partner-side information assets and connections were compromised and used by an external entity to attack the victim’s systems in 57% of breaches involving a business partner. Though not a willing accomplice, the partner’s lax security practices - often outside the victim’s control - undeniably allow such attacks to take place. Exacerbating this situation, the victim organization frequently lacks measures to provide accountability for partner-facing systems. This contributed to the 21 percent of breaches in which partner involvement was evident but specific persons were not identified.”

M. E. Kabay, PhD, CISSP-ISSMP, specializes in security and operations management consulting services and teaching. He is Chief Technical Officer of Adaptive Cyber Security Instruments, Inc. and Associate Professor of Information Assurance in the School of Business and Management at Norwich University. Visit his Web site for white papers and course materials.

  • Share/Email
  • Tweet This
  • Comment
  • Print

Comments (1)
Login
Forgot your account info?

Data BreachesBy davidscott on July 9, 2008, 11:15 amI just read your excellent and timely Data Breach Report. Senior management does not always appreciate the wide avenues for breach in their very organizations....

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed