Risk
10/10/2010
02:41 PM
George V. Hulme
George V. Hulme
Commentary
Connect Directly
RSS
E-Mail
50%
50%

Insiders Still Remain Potential Powerful Threat

While malware and hacker attacks continue to make the headlines, recent events remind us that insiders still pose a potent threat.

While malware and hacker attacks continue to make the headlines, recent events remind us that insiders still pose a potent threat.Consider Mathew J. Schwartz's story, Feds Bust Akamai Insider, about the man who allegedly tried to provide sensitive and confidential information to someone he thought was a foreign government:

According to the allegations, Doxer emailed a foreign county's Boston consulate offering to share information, stating that his goal "was to help our homeland and our war against our enemies." Allegedly, he also requested $3,000, on account of the risks he was taking. The foreign government, in turn, notified the United States government, which one year later launched an 18-month investigation.

According to Schwartz, and other reports, Doxer allegedly shared secrets relating to Akamai's IT and physical security, and shared details on thousands of Akamai customers and its 1,300 employees.

In other insiders news this week, there is the case of Rajendrasinh Babubha Makwana who was found guilty by a federal jury of planting a logic bomb on Fannie Mae's systems after getting fired. Experts have said that had the logic bomb been triggered, it could have caused millions in damage and shut down operations.

From our story, Fannie Mae Insider Convicted For Planting Malware:

Trial testimony detailed how Makwana was fired on October 24, 2008, and ordered to return all Fannie Mae-issued IT equipment, including his laptop. Five days later, however, "a Fannie Mae senior engineer discovered a malicious script embedded in a routine program," said the FBI.

"A subsequent analysis of the script, computer logs, Makwana's laptop, and other evidence revealed that Makwana had transmitted the malicious code on October 24, 2008, which was intended to execute on January 31, 2009," said the FBI.

"The malicious code was designed to propagate throughout the Fannie Mae network of computers and destroy all data, including financial, securities, and mortgage information."

Insiders like these, with legitimate access to information, are a tough threat to stop. Though the threat can be (somewhat) mitigated with increased monitoring for abnormalities in networks and systems as well as database access. That's the good news in the Fannie May story: vigilance saved the organization from suffering a successful - and what could had of been devastating - attack.

Though our own Department of Defense must not think current technologies are up to thwarting the insider threat. Why else would have DARPA announced this program to develop new technologies to spot and stop insider threats.

For my security and technology observations throughout the day, follow me on Twitter.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-6651
Published: 2014-07-31
Multiple directory traversal vulnerabilities in the Vitamin plugin before 1.1.0 for WordPress allow remote attackers to access arbitrary files via a .. (dot dot) in the path parameter to (1) add_headers.php or (2) minify.php.

CVE-2014-2970
Published: 2014-07-31
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-5139. Reason: This candidate is a duplicate of CVE-2014-5139, and has also been used to refer to an unrelated topic that is currently outside the scope of CVE. This unrelated topic is a LibreSSL code change adding functionality ...

CVE-2014-3488
Published: 2014-07-31
The SslHandler in Netty before 3.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted SSLv2Hello message.

CVE-2014-3554
Published: 2014-07-31
Buffer overflow in the ndp_msg_opt_dnssl_domain function in libndp allows remote routers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted DNS Search List (DNSSL) in an IPv6 router advertisement.

CVE-2014-5171
Published: 2014-07-31
SAP HANA Extend Application Services (XS) does not encrypt transmissions for applications that enable form based authentication using SSL, which allows remote attackers to obtain credentials and other sensitive information by sniffing the network.

Best of the Web
Dark Reading Radio