Hackers target data centers for extortion

Opinion
Nov 1, 20053 mins

* Cyber-extortion

Many companies have faced a scary situation: cyber-extortion, in which hackers will try to extort a fee while holding a company’s data hostage.

In some of the first cases of cyber-extortion, hackers would try to provide “security services” with a veiled threat of public embarrassment. In these cases, the hackers would find a vulnerability and offer their “services” to help the company close the hole. Implicitly at first, the hackers would threaten to reveal their methods to other “less scrupulous” hackers if they did not receive a fee.

Gambling sites and pornography sites were among the first victims of such cyber-extortion tactics, presumably because they are often hosted in obscure jurisdictions and avoid the spotlight of law enforcement anyway. Fortunately, the FBI quickly recognized that such tactics would not remain on the “seedy” side of town for long.

Soon large multinationals in the banking and e-commerce domains were blackmailed over credit-card data. The scariest implication of these tactics is that the perpetrators are a very different breed from the hackers of yore. It’s the difference between a juvenile prank of toilet-papering your home and someone throwing a firebomb through your bedroom window. Hacking groups are no longer predominantly made of inquisitive geeks with a point to prove – the new hacking groups are backed, funded and driven by organized crime. Hacking has come of age.

With consolidation of data into data centers and the erosion of the traditional security perimeter, the new focus of hackers and security professionals is in the storage arrays, applications and databases that reside in the data center. A layered approach to data-center security is the predominant strategy for data protection.

Part of the layered approach is the recognition that the data center has to be open to access by partners, suppliers and customers in the “information supply chain” of today’s distributed and interconnected enterprise. That means increasing dependence on strong authentication, federated identity and comprehensive identity management systems.

Database security should be another area of concern. Even though all database vendors offer access-control features, these represent a good starting point, not the complete package of security controls. Inline appliances that monitor SQL access can provide an additional layer of defense, one that is sensitive to the context of a SQL query. We expect to see much more reliance on statistical and behavioral analysis of queries in the future.

When attackers knock on your data center door and try to gain access, they may be about to pull a much nastier trick on you than you expected. Organized crime has found a new playing field – and it is your data center.