The Four Most Common Security Dangers For all the complexity of security, the most common security dangers are downright mundane. They’re not due to the arcane arts of the most skilled hackers or some cunning exploit; they’re out there in plain sight. "A successful attack depends on a combination of four things that don’t have a lot to do with the attacker," says Forrester Research analyst Paul Stamp. "It’s usually something like social engineering, a breakdown in process or the absence of process. It could have something to do with a simple technical vulnerability or insider abuse. But it’s usually a combination of two or more of those four factors." The thing that should send chills up the spine of anyone who manages a network open to the Internet – which is to say, virtually all networks – is the fact that all of these vulnerabilities can be easily caught and fixed. Because they’re so common, obvious, or at least mundane, however, they are often the last place you’ll look for danger. Social Engineering: Just this summer, the British Department of Defense – which should be on the list of people who should be wise to this – was the victim of a targeted Trojan attack. "People were sent CDs with marketing material," Stamp says. "In fact, it installed a targeted Trojan that collected confidential information." The bottom line is that even smart people can be victimized by social engineering. The first step toward protection, Stamp says, is as basic as education. "It truly is a boring recommendation, but we have to educate users and back that up with action," he says. "The time has passed for us to tolerate fools. We have to be serious about this and take disciplinary action against people who don’t do what they’re supposed to do. The stakes are too high." Process Errors: Stamp points to the Choicepoint case earlier this year as a prime example of a breakdown in process. "Criminals were able to open fraudulent accounts with Choicepoint because the process for opening an account didn’t involve checking to see if the client was a real company," he says. "It was as simple as that." Moreover, if companies are going to use technologies like networks, wireless and mobile devices, they have to have some way of dealing with everything from absent—mindedness to incompetence and malice. Mistakes happen, of course, but they can turn into disasters if you don’t respond to them effectively. "It could be something as simple as someone leaving a Blackberry in a cab," Stamp says. "Surprisingly few companies have policies for dealing with Blackberries when they’re out of the office, and the whole point of a Blackberry is to be out of the office." Technical vulnerabilities: Inside Abuse: Part of the problem is that no one wants to believe that one of their own could be the problem, and inside abuse is often swept under the carpet. But Stamp is adamant that just because you can’t or chose not to see the problem doesn’t mean it isn’t there. At the end of the day, all of these common dangers can be dealt with, it only takes the will to clean up processes, patch systems, and make sure that users are doing what they’re supposed to be doing. "It has to be both a change in attitude and the adoption of newer, smarter technologies," Stamp says. "That means designing the network to be secure from the ground up, and that includes the people as well as the technology." About the Author with Permission |