Perimeter
6/19/2009
02:40 PM
John H. Sawyer
John H. Sawyer
Commentary
50%
50%

Data Leakage Through Nontraditional Networks

Securing our company's data is our job. We build up layers of defense to protect it when it is housed within our corporate network and corporate computer systems. Firewalls, VPNs, encryption, and data leakage prevention all help in some way to protect the data that we don't want anyone else to have. Sometimes, however, we are stuck in the situation where we don't control the network or systems that portions of our data ends up on.

Securing our company's data is our job. We build up layers of defense to protect it when it is housed within our corporate network and corporate computer systems. Firewalls, VPNs, encryption, and data leakage prevention all help in some way to protect the data that we don't want anyone else to have. Sometimes, however, we are stuck in the situation where we don't control the network or systems that portions of our data ends up on.A few examples that come to mind are third party contractors, business partners and cloud service providers. We are either forced by business decisions or the desire to offload storage and processing to someone who can do it cheaper. Either way, our data ends up where we are not in direct control of the network nor are we responsible for securing the network it resides on.

What about some other examples of networks you don't control that might end up with your data? Try to think of something that is more non-traditional but highly likely to be unauthorized? Did I hear P2P? If not, let me remind you of the recent leak of sensitive Marine One blueprints over P2P from a defense contractor. That was definitely data that the government didn't want outside of their control but it made it out and likely because of misconfigured P2P software client.

Having your data leaked via P2P is a scary situation to consider but it has happened and will continue to happen. New technologies are currently being developed that could make it even easier. The recent announcement by the Opera Web browser development team is the most recent. The technology called Unite will include a mini Web server in each Web browser allowing users to share files and folders directly to users across the Internet.

Do you really want all your users and their systems to become web servers? I didn't think so...The easy fix is to not use Opera, but that doesn't mean your contractors or home users won't be using it.

Just thinking about the possibilities for abuse gives me a headache, but don't worry about me, there's more on the horizon to be concerned about. Take a look at "Veiled," a new browser-based darknet that will be demonstrated at BlackHat next month. It sounds as if it could be as easy as getting someone to open an HTML-based e-mail or clicking on a link to pull them into the darknet. From there, who knows what could happen.

Besides policy and contracts that state P2P can't be used on systems that access sensitive data and such, what are you using out there to protect yourselves? DLP is certainly an option but is limited when considering data that doesn't live on your network. There are also monitoring companies who search for your data on P2P network, or you could do it manually.

It's an interesting problem that's going to get worse with these new technologies and more companies moving their data to the cloud. How do you plan to deal with it?

John H. Sawyer is a senior security engineer on the IT Security Team at the University of Florida. The views and opinions expressed in this blog are his own and do not represent the views and opinions of the UF IT Security Team or the University of Florida. When John's not fighting flaming, malware-infested machines or performing autopsies on blitzed boxes, he can usually be found hanging with his family, bouncing a baby on one knee and balancing a laptop on the other. Special to Dark Reading.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Title Partner’s Role in Perimeter Security
Title Partner’s Role in Perimeter Security
Considering how prevalent third-party attacks are, we need to ask hard questions about how partners and suppliers are safeguarding systems and data.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-0543
Published: 2015-07-05
EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2015-0544
Published: 2015-07-05
EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly generate random values for session cookies, which makes it easier for remote attackers to hijack sessions by predicting a value.

CVE-2015-2721
Published: 2015-07-05
Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not properly determine state transitions for the TLS state machine, which allows man-in-the-middle attacke...

CVE-2015-2722
Published: 2015-07-05
Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 allows remote attackers to execute arbitrary code via vectors involving attachment of an XMLHttpRequest object to a shared worker.

CVE-2015-2724
Published: 2015-07-05
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code v...

Dark Reading Radio
Archived Dark Reading Radio
Marc Spitler, co-author of the Verizon DBIR will share some of the lesser-known but most intriguing tidbits from the massive report