Risk
10/10/2010
02:41 PM
George V. Hulme
George V. Hulme
Commentary
Connect Directly
RSS
E-Mail
50%
50%

Insiders Still Remain Potential Powerful Threat

While malware and hacker attacks continue to make the headlines, recent events remind us that insiders still pose a potent threat.

While malware and hacker attacks continue to make the headlines, recent events remind us that insiders still pose a potent threat.Consider Mathew J. Schwartz's story, Feds Bust Akamai Insider, about the man who allegedly tried to provide sensitive and confidential information to someone he thought was a foreign government:

According to the allegations, Doxer emailed a foreign county's Boston consulate offering to share information, stating that his goal "was to help our homeland and our war against our enemies." Allegedly, he also requested $3,000, on account of the risks he was taking. The foreign government, in turn, notified the United States government, which one year later launched an 18-month investigation.

According to Schwartz, and other reports, Doxer allegedly shared secrets relating to Akamai's IT and physical security, and shared details on thousands of Akamai customers and its 1,300 employees.

In other insiders news this week, there is the case of Rajendrasinh Babubha Makwana who was found guilty by a federal jury of planting a logic bomb on Fannie Mae's systems after getting fired. Experts have said that had the logic bomb been triggered, it could have caused millions in damage and shut down operations.

From our story, Fannie Mae Insider Convicted For Planting Malware:

Trial testimony detailed how Makwana was fired on October 24, 2008, and ordered to return all Fannie Mae-issued IT equipment, including his laptop. Five days later, however, "a Fannie Mae senior engineer discovered a malicious script embedded in a routine program," said the FBI.

"A subsequent analysis of the script, computer logs, Makwana's laptop, and other evidence revealed that Makwana had transmitted the malicious code on October 24, 2008, which was intended to execute on January 31, 2009," said the FBI.

"The malicious code was designed to propagate throughout the Fannie Mae network of computers and destroy all data, including financial, securities, and mortgage information."

Insiders like these, with legitimate access to information, are a tough threat to stop. Though the threat can be (somewhat) mitigated with increased monitoring for abnormalities in networks and systems as well as database access. That's the good news in the Fannie May story: vigilance saved the organization from suffering a successful - and what could had of been devastating - attack.

Though our own Department of Defense must not think current technologies are up to thwarting the insider threat. Why else would have DARPA announced this program to develop new technologies to spot and stop insider threats.

For my security and technology observations throughout the day, follow me on Twitter.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3345
Published: 2014-08-28
The web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software) 4.0 does not properly check authorization for administrative web pages, which allows remote attackers to modify the product via a crafted URL, aka Bug ID CSCuq31503.

CVE-2014-3347
Published: 2014-08-28
Cisco IOS 15.1(4)M2 on Cisco 1800 ISR devices, when the ISDN Basic Rate Interface is enabled, allows remote attackers to cause a denial of service (device hang) by leveraging knowledge of the ISDN phone number to trigger an interrupt timer collision during entropy collection, leading to an invalid s...

CVE-2014-4199
Published: 2014-08-28
vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, allows local users to write to arbitrary files via a symlink attack on a file in /tmp.

CVE-2014-4200
Published: 2014-08-28
vm-support 0.88 in VMware Tools, as distributed with VMware Workstation through 10.0.3 and other products, uses 0644 permissions for the vm-support archive, which allows local users to obtain sensitive information by extracting files from this archive.

CVE-2014-0761
Published: 2014-08-27
The DNP3 driver in CG Automation ePAQ-9410 Substation Gateway allows remote attackers to cause a denial of service (infinite loop or process crash) via a crafted TCP packet.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
This episode of Dark Reading Radio looks at infosec security from the big enterprise POV with interviews featuring Ron Plesco, Cyber Investigations, Intelligence & Analytics at KPMG; and Chris Inglis & Chris Bell of Securonix.