Risk
10/10/2010
02:41 PM
George V. Hulme
George V. Hulme
Commentary
Connect Directly
RSS
E-Mail
50%
50%

Insiders Still Remain Potential Powerful Threat

While malware and hacker attacks continue to make the headlines, recent events remind us that insiders still pose a potent threat.

While malware and hacker attacks continue to make the headlines, recent events remind us that insiders still pose a potent threat.Consider Mathew J. Schwartz's story, Feds Bust Akamai Insider, about the man who allegedly tried to provide sensitive and confidential information to someone he thought was a foreign government:

According to the allegations, Doxer emailed a foreign county's Boston consulate offering to share information, stating that his goal "was to help our homeland and our war against our enemies." Allegedly, he also requested $3,000, on account of the risks he was taking. The foreign government, in turn, notified the United States government, which one year later launched an 18-month investigation.

According to Schwartz, and other reports, Doxer allegedly shared secrets relating to Akamai's IT and physical security, and shared details on thousands of Akamai customers and its 1,300 employees.

In other insiders news this week, there is the case of Rajendrasinh Babubha Makwana who was found guilty by a federal jury of planting a logic bomb on Fannie Mae's systems after getting fired. Experts have said that had the logic bomb been triggered, it could have caused millions in damage and shut down operations.

From our story, Fannie Mae Insider Convicted For Planting Malware:

Trial testimony detailed how Makwana was fired on October 24, 2008, and ordered to return all Fannie Mae-issued IT equipment, including his laptop. Five days later, however, "a Fannie Mae senior engineer discovered a malicious script embedded in a routine program," said the FBI.

"A subsequent analysis of the script, computer logs, Makwana's laptop, and other evidence revealed that Makwana had transmitted the malicious code on October 24, 2008, which was intended to execute on January 31, 2009," said the FBI.

"The malicious code was designed to propagate throughout the Fannie Mae network of computers and destroy all data, including financial, securities, and mortgage information."

Insiders like these, with legitimate access to information, are a tough threat to stop. Though the threat can be (somewhat) mitigated with increased monitoring for abnormalities in networks and systems as well as database access. That's the good news in the Fannie May story: vigilance saved the organization from suffering a successful - and what could had of been devastating - attack.

Though our own Department of Defense must not think current technologies are up to thwarting the insider threat. Why else would have DARPA announced this program to develop new technologies to spot and stop insider threats.

For my security and technology observations throughout the day, follow me on Twitter.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0972
Published: 2014-08-01
The kgsl graphics driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly prevent write access to IOMMU context registers, which allows local users to select a custom page table, and consequently write ...

CVE-2014-2627
Published: 2014-08-01
Unspecified vulnerability in HP NonStop NetBatch G06.14 through G06.32.01, H06 through H06.28, and J06 through J06.17.01 allows remote authenticated users to gain privileges for NetBatch job execution via unknown vectors.

CVE-2014-3009
Published: 2014-08-01
The GDS component in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 through 11.0 and InfoSphere Master Data Management Server for Product Information Management 9.0 and 9.1 does not properly handle FRAME elements, which makes it easier for remote authenticated users to conduct ph...

CVE-2014-3302
Published: 2014-08-01
user.php in Cisco WebEx Meetings Server 1.5(.1.131) and earlier does not properly implement the token timer for authenticated encryption, which allows remote attackers to obtain sensitive information via a crafted URL, aka Bug ID CSCuj81708.

CVE-2014-3534
Published: 2014-08-01
arch/s390/kernel/ptrace.c in the Linux kernel before 3.15.8 on the s390 platform does not properly restrict address-space control operations in PTRACE_POKEUSR_AREA requests, which allows local users to obtain read and write access to kernel memory locations, and consequently gain privileges, via a c...

Best of the Web
Dark Reading Radio