![]() |
Data security and privacy: A holistic approach Download here |
"Even after the culprits are caught and prosecuted, their victims are still faced with the difficult task of having to repair their credit ratings and financial reputations. In some cases, that process can take years,” said Queens DA Richard A. Brown.
Using credit-card numbers provided by a loose network of overseas criminal syndicates, online black market dealers, and skimmers, the 110 crooks indicted by the authorities were allegedly able to set up a system to clone cards and engage in spending sprees and wholesale fencing operations that stole more than $13 million in goods and services. The Queens DA office said that with the New York Police Department, it was able to unravel five different crime rings with different bosses but an interwoven patchwork of common fake card manufacturers, shoppers, fencers and more.
“This is by far the largest -- and certainly among the most sophisticated -- identity theft/credit-card fraud cases that law enforcement has come across,” Brown said.
All of the moving parts and sophistication of organization used by the criminals in these rings illustrate what happens once the criminal element is able to infiltrate a database to steal credit-card and other financial information. Many of the crimes perpetrated by the indicted in this case were fueled not only by skimmers, but also by international and local suppliers who had already done the hacking work to compile lists of stolen card numbers.
"The materials were alleged to have come from overseas -- unknown individuals in such places as Russia, Libya, Lebanon, and China -- or from statewide suppliers, such individuals who worked in a restaurant or bar, retail store, or financial institution and used a skimming device to swipe a consumer’s credit card information or who obtained credit card accounts through illegal web sites," the Queens DA office said in a statement about the case.
According to Josh Shaul, CTO of Application Security, Inc., the ready availability of these numbers should make organizations think more seriously about monitoring database activity.
"Outsiders are the new breed of insiders; there's just so many ways an outsider can get into the database, whether it's through SQL injection vulnerabilities in a website or by loading up malware on somebody's laptop or some other endpoint," Shaul says. "It has become almost trivial for an attacker to find some position on the inside of a target network and start working from there, and once they find hat chink in the armor, that lets them get in. They may not be an authorized user, but they're just as much an insider as anyone else on the network. And so from that respect, I feel like monitoring your data, the stuff you really care about is critical."
According to some, this case also bears some lessons on keeping better tabs on insiders to look for malicious behavior and to better correlate events to look for patterns of a wider ring of fraud across multiple users and events.
"In general, I think that this points at the very interesting area of data correlation, specifically in the work done through security information and event management and behavioral analysis systems," says Phil Lieberman, president of Lieberman Software. "It is a second-order goal. The first order is detecting the fraud. The second order is tying together who all the players are."
In this recent case, some of the fraud-ring bosses tapped inside employees within retail or banking establishments to use their account access to find out which stolen credit card offered the best opportunity for high value theft. And one even paid an attorney in designer shoes to advise on how to carry out his thieving ways and avoid detection. Clearly, the faster an organization can detect employees on the inside working for a criminal element, the less damage will be wrought in these cases. That means keeping better tabs on how they are looking up database information across multiple applications and systems.
"So folks have got to be monitoring access to their sensitive and valuable data, and they've got to make sure that all of the access that they see is legitimate," Shaul says, "which means not just turning on some system to monitor access, but looking at the access that's actually there and doing something about the suspicious, malicious, and the anomalous."
This has been increasingly a focus for SIEM vendors of late, says Joe Gottlieb, CEO for SIEM vendor SenSage.
"Nowadays it is about actually looking at the identity of the user, what other identities that user has, what other permissions and systems that user has, and what systems they show up on," he says. "All of that is context now for the types of insider threats that we have to protect against and some of the collusions, potentially, between insiders and outsiders."
Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.
| To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy. |
Securing The Data Warehouse
Many enterprises are building data warehouses to centralize the ever-increasing information flowing through their organizations into useful repositories. This makes good business sense, but it opens up a slew of concerns from a security standpoint. IT professionals can apply many of the same security best practices used with databases, but there are new lessons to be learned as well.
Defend Your Data From Malicious Insiders
The biggest threat to your company?s most sensitive data may be the employee who has legitimate access to corporate databases but less-than-legitimate intentions. And while the incidence of insider data breaches has decreased, external attacks often imitate them--and do serious damage. Follow our advice to mitigate the risk.
Ensuring Secure Database Access
Role-based access control based on least user privilege is one of the most effective ways to prevent the compromise of corporate data. But proper provisioning is a growing challenging, due to the proliferation of "big data," NoSQLdatabases, and cloud-based data storage.
Other reports from the Database Security Tech Center:
| Sponsored by: |
Establishing a Strategy for Database Security is No Longer Optional
As databases continue to grow in size, complexity and importance, enterprises struggle to identify the most appropriate controls regarding their use and misuse. The report identifies best practices, including: Implementing database activity monitoring to mitigate the high levels of risk from database vulnerabilities, and address audit findings in areas such as database segregation of duties and change management; using data security measures, such as data masking and data encryption; and monitoring privileged-user access and access to critical data.
Database Activity Monitoring Is Evolving Into Database Audit and Protection
In this report, Gartner writes that "Database audit and protection (DAP) represents an evolutionary advance in database activity monitoring tools." DAP suites provide comprehensive, cross-platform support in heterogeneous database environments to protect sensitive data from inappropriate use. Organizations are increasingly concerned with optimizing database security and mitigating risks associated with database vulnerabilities.
Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
Data security presents a multi-dimensional challenge in today's complex IT environment. Multiple access paths and permission levels have resulted in a broad array of security threats and vulnerabilities. We invite you to read this new eBook: "Protecting against database attacks and insider threats" to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.
Demo: Distributed Database Security with Real-time Monitoring and Audit Protection
Organizations across the globe continue to experience compromised data caused by malicious attacks, web application vulnerabilities or unauthorized changes. View this demo and learn how IBM InfoSphere Guardium? database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.
Look Beyond Native Database Auditing To Improve Security, Audit Visibility, And Real-Time Protection
Today's attacks on enterprise databases are more sophisticated than ever, and they occur so fast that it's often difficult to stop them in real time. Despite significant efforts to protect enterprise databases, the number of records breached has grown each year - due to all types of internal and external attacks and violations of corporate policy.
MORE NEWSFEED >>>