Microsoft Outlook Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Monday, 29 November 2010

Insider threat behind Wikileaks cybersecurity saga

Posted on 10:18 by Unknown

London, 29th November 2010 - The Wikileaks saga of the last few days, which climaxed with the release of  the first batch of more than 250,000 secret and confidential diplomatic cables sent by US embassies around the world published last night, are a classic example of what can happen when the evolving insider security threat is ignored says Imperva.

According to Amichai Shulman, CTO with the data security specialist, the saga - which took a curious twist on Sunday when Wikileaks' servers came under a distributed denial of service attack (http://bit.ly/gNhimg) - shows that organisations of all sizes seem to be preoccupied with defending against external attacks on their digital data assets, and are ignoring the internal security threat issue.

"Yes, there are hackers out there, but IT history has shown that the rogue employee is also a threat. The banking community is now starting to take action (http://bit.ly/enKRnq) to protect its assets, but organisations have a long way to go before they can truly tackle the very real risks that insider threats pose to their reputation and integrity," he said.

According to the Guardian, Bradley Manning, 22 – a soldier (an intelligence analyst), has admitted to stealing the information and in fact stated how easy it was to gain access to the files - http://bit.ly/fv4DCe: 

It was childishly easy, according to the published chatlog of a conversation that Manning had with a fellow-hacker. "I would come in with music on a CD-RW labelled with something like 'Lady Gaga' … erase the music … then write a compressed split file. No one suspected a thing ... [I] listened and lip-synched to Lady Gaga's Telephone while exfiltrating possibly the largest data spillage in American history." He said that he "had unprecedented access to classified networks 14 hours a day 7 days a week for 8+ months".

Shulman says that the source of the leak is believed to be the same individual responsible for the 75,000 document leak earlier this year - identified as a low ranking soldier who abused legitimate access to the information, he explained. This is the second time this has happened without any measures put into place to stop this happening. This illustrates the potential damage that insiders can cause in an organization

And, says the Imperva CTO, as with most incidents of this type, the most noticeable sign of problems should have been the easily observable intensive access to multiple documents by an authorised user. However, it is very difficult for organizations today to control access to files at an individual level. The rate with which sensitive information is generated in the form of files is ever growing, collaborative behavior is widely encouraged by management and employee turnover rates are high. Thus, while organizations must control and monitor individual access to specific files based on their contents, they must monitor employee behavior with respect to files in general.

"Any user retrieving large numbers of documents a day should raise an alert on a good business IT security system. This presumes, of course, that the organisation is not pre-occupied with conventional security and has ignored the abuse of data access privileges," he said.

"This embarrassing fiasco - which is certain to drag on for some time - shows that the internal threat is not necessarily about unauthorised access to data, but rather the abuse of legitimate access," he added.

"Organisations need to wake up to the complexities of internal threats, rather than simply relying on conventional IT security systems."

For more on the Wikileaks saga: http://bit.ly/fuPFiW

For more on Imperva: www.imperva.com

Source: Eskenzi PR

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Open Source Software in Business & Government
    by Michael Smith (Veshengro) Lots of Open Source in use in mainland Europe, including EU member states, very little in the UK and less still...
  • Infosecurity Europe 2011 Hall of Fame nominations now open
    London UK, February  2011 – The time is ripe to elevate the greatest movers and shakers in the world of information security as nominations ...
  • Tufin unveils new functionality & updated PCI DSS 2.0 compliance reporting
    TUFIN TECHNOLOGIES UNVEILS enhanced firewall operations management functionality and UPDATEd pci dss 2.0 compliance reporting New Perm...
  • Web 2.0 services are the next security hurdle says 360°IT – The IT Infrastructure Event
    Planning is are now well under way for the first 360°IT – The IT Infrastructure Event, due to take place at London's Earls Court this co...
  • Safer Internet Day - The role of Security within Social Networks
    Amichai Shulman – CTO and co-founder of Imperva Last week researchers unveiled a “ dating database ” consisting of 250,000 users. This was...
  • ISACA’s EuroCACS Examines Data Protection, Cloud Computing and Social Networking
    ISACA’s EuroCACS Examines Data Protection, Cloud Computing and Social Networking 20-23 March 2011, Manchester, UK Rolling Meadows, IL,...
  • Experts warn about risks of multi-tasking on new iPhone 4.0 OS
    Fortify Software warns companies to beware multi-tasking aspects of new iPhone 4.0 operating system Following a rash of news reports about...
  • Experts says trashed hard drive fiasco at Pfizer could have been avoided with Encryption
    Credant says trashed hard drive at Pfizer would not have happened if data had been encrypted Credant Technologies says that a security gaffe...
  • IT services provider, FORT, brings AVG to Irish market
    by Michael Smith (Veshengro) ISP customers to benefit from complete Internet security solution London, UK – AVG, the world’s most downloaded...
  • Lieberman Software and Q1 Labs Partner to stop insider threats
    Joins Q1 Labs Security Intelligence Partner Program London – February 1, 2011 Organisations seeking to eliminate the potential for anony...

Categories

  • ASUS
  • AVG Link Scanner
  • BeCrypt
  • book review
  • Brocade
  • Codenomicon
  • Columbian USB stick loss
  • computer recycling
  • Conficker worm
  • Credant Technologies
  • cyber crime
  • Cyber-Ark
  • Cyber-Ark®
  • Data Center
  • data encryption
  • DeviceLock
  • Digital Pathways
  • diskGenie
  • Eclypt
  • Eee PC
  • Eee PC Seashell 1008HA
  • F5 Networks
  • Facebook
  • Finjan
  • Finjan Inc.
  • Finjan MCRC
  • Firewall Management
  • Fortify
  • Fortify 360
  • Fortify Software
  • Fortify® Software
  • gadgets
  • Google
  • Google Chrome
  • green computing
  • green IT
  • IBM
  • Infosec
  • Infosec Europe 2009
  • Infosecurity Adviser
  • Infosecurity Europe
  • Infosecurity Europe 2009
  • Internet privacy
  • iStorage
  • iStorage diskGenie
  • iStorage Ltd.
  • Juniper Networks
  • Lakeland
  • Lapdesk
  • LLC
  • Logitech
  • malware
  • ManageEngine
  • McAfee International Ltd
  • MI6
  • MI6 data loss
  • Microsoft
  • MiFi™ 2352
  • Mio
  • Mobile Broadband
  • MS Office
  • National Cybersecurity Advisor
  • Navman
  • Navman Spirit
  • Netac
  • Novatel
  • Novatel Wireless Intelligent Mobile Hotspot 2352
  • OneClick IntelliPanel Desktop
  • online social media
  • open source
  • OpenOffice.org
  • Optenet
  • Origin Data Locker
  • Origin Storage
  • PNDs
  • product review
  • Red
  • SaaS
  • Sat Nav
  • saving energy
  • Security
  • Shavlik Technologies
  • SIS
  • spam
  • Stonewood Group
  • Storage Area Networks
  • Storage Expo
  • Storage Expo 2009
  • Sun Microsystems
  • Swine Flu
  • Syphan Technologies
  • Throwing Sheep in the Boardroom
  • Tufin Technologies
  • Twitter
  • U256
  • Unisys Security Index
  • USB drives
  • Vektor
  • VisionRacer
  • VisionRacer VR3
  • VMware
  • Weast
  • Web Apps Security
  • WebFilter PC Solution
  • WebSpy
  • XSS-driven attacks

Blog Archive

  • ►  2012 (1)
    • ►  January (1)
  • ►  2011 (67)
    • ►  December (1)
    • ►  April (1)
    • ►  March (14)
    • ►  February (30)
    • ►  January (21)
  • ▼  2010 (192)
    • ►  December (20)
    • ▼  November (22)
      • New TwinStrata and Scality partnership delivers tu...
      • TUFIN TECHNOLOGIES RANKS TENTH IN THE 2010 DELOITT...
      • Data Security Feels the Heat
      • Insider threat behind Wikileaks cybersecurity saga
      • Stuxnet - The First Worm of Many for SCADA?
      • Tufin warns IT departments to prepare for Christma...
      • Trusteer warns of growing security crisis for mobi...
      • Extra security needed as hackers repurpose ZeuS to...
      • Most employees will steal company secrets if they ...
      • Data Encryption Systems Wins ‘Encryption Solution ...
      • Credant Technologies say cloud-based crack of SHA-...
      • Incapsula Launches Cloud-based Web Application Fir...
      • Account Management in Dell Remote Access Controlle...
      • Government Hacking and Smartphone attacks Lead the...
      • According to Trusteer 2FA powerless against Real t...
      • Idappcom warns `pay-for-bugs' approach by ITsec ve...
      • TUFIN TECHNOLOGIES WINS the PRESTIGIOUS 2010 Compu...
      • ISACA Survey: Employees Will Spend Six Hours Shop...
      • Trusteer Predicts Financial Malware Attacks will E...
      • Banks need to wake up and smell the security coffe...
      • Security Audit and Penetration Testing Just Got Be...
      • Take PRIDE in Your PC with ASUS
    • ►  October (19)
    • ►  September (5)
    • ►  August (8)
    • ►  July (5)
    • ►  June (22)
    • ►  May (13)
    • ►  April (11)
    • ►  March (13)
    • ►  February (27)
    • ►  January (27)
  • ►  2009 (240)
    • ►  December (25)
    • ►  November (9)
    • ►  October (21)
    • ►  September (19)
    • ►  August (30)
    • ►  July (35)
    • ►  June (30)
    • ►  May (21)
    • ►  April (42)
    • ►  March (8)
Powered by Blogger.

About Me

Unknown
View my complete profile