Free Newsletters
InfoWorld Daily

InfoWorld
Log-in | Register

Future-proof your IT security

Small, targeted incursions are the next wave of attacks compromising enterprise networks. Know the enemy


Neither government nor enterprise IT security defenses, says Mudge, are geared for such low-key incursions. “They have a fixed mind-set, which is border defense and standard kinds of probing and port scans. The idea that a foreign cyberforce could infiltrate over the period of a few years, then stand up and deny you the use of your own systems is foreign to them,” he says. “But that’s the scenario we have to start working on.”

DOWNLOAD PDF

2006 InfoWorld Security Survey


MORE ON 2006 IT SECURITY


Alan Paller, research director at the SANS Institute, agrees. “With spear phishing and [zero-day] vulnerabilities there’s really no perimeter. And once somebody’s in, if nobody is watching, this stuff spreads like a metastasis.”

Not to mention that the perpetrators may be very close to home. Cybertrust data shows that, in about 10 percent of all incidents it is asked to investigate, insiders are the source of the trouble. In another 30 percent, attacks come by way of connections with business partners and other trusted parties, says Kerry Bailey, senior vice president of global services at Cybertrust.

“The first problem is that these people didn’t necessarily break in. They may already have access, so devices like firewalls and IDS aren’t going to do anything. You’ve got to allow employees to have access to do their job,” says network-defense expert Eric Cole, CTO of The Sytex Group and an adjunct professor at New York Institute of Technology and Georgetown University.

That means IT staff must understand how attacks play out within the network: how software vulnerabilities in programs can allow attackers to gain a foothold and how, from there, they can compromise other systems, access sensitive data, and “exfiltrate” it from your network, Mudge says.

In other words, nameless hackers have penetrated your network and covered their tracks, but they’re not invisible. In most cases, infiltrators of enterprise networks don’t know where the information they want is located and have to look for it. In so doing, they often give away their presence by violating what Mudge terms the physics of networks.

“Think about your internal environment. It’s pretty well defined compared to the Internet, where you truly have distributed data. If I saw somebody accessing a bunch of diff databases or database servers for finance, marketing, R&D, that doesn’t make any sense,” Mudge says, providing one example.

Companies such as Intrusic, which Mudge helped found, sell products that look for those kinds of “tells.” And more companies are investing in SEM (security event management) tools that correlate data from multiple security products.

But security experts agree that effective technology to combat the insider threat is still off in the future. Meanwhile, IT managers should train qualified internal incident response teams to look for telltale signs — and prepare dynamic and resilient responses to attacks so that panic doesn’t ensue when things start breaking.

Wars of attrition

What about preventing attacks before they start? Unfortunately, effective prosecution of organized cybercrime groups and state-sponsored hackers is a long way off. Realistically, the best strategy is a smart, flexible defense that makes attacks increasingly costly, causing hackers to simply move on.

Paul F. Roberts is a senior editor at InfoWorld.
Continued
« PREVIOUS PAGE | 1 | 2 | 3 | 4 | NEXT PAGE » 


Talkback:

commentPost a Comment

 

MOST COMMENTS

 
 





COMPREHENSIVE DATA PROTECTION AND DISASTER RECOVERY
Traditional backup and recovery is becoming irrelevant. You need more. Watch this InfoWorld and Dell Equallogic webcast to learn the current trends in Comprehensive Data Protection and Disaster Recovery for VMware Virtual Infrastructure. Sponsored by Dell Equallogic:

»  Click here to view this Webcast
  Protection for Remote Sites and Branch Offices
This Whitepaper reviews the challenges of creating appropriate data protection, especially for small and midsize companies with remote and branch offices. It offers suggestions on how you can choose the most appropriate data protection solution for your company's needs. Sponsored by Overland

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 
 

Video

 
 
 

Podcasts

 
IFW Daily 12/04/2008

Sun enters RIA realm with JavaFX, Adobe says it will cut 600 jobs, AMD...

 
 
 

Columnists

 
 
 

Resource Center


Ads by techwords beta  [See your link here]
 




Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist
TecChannel :: TecCommunity