Feeds

Old people can sabotage software too

Games insiders play

The Power of One eBook: Top reasons to choose HP BladeSystem

RSA Software teams must act to protect systems and development projects from revenge attacks by disgruntled current and former employees.

So says Carnegie Mellon Software Engineering Institute's CERT, which is advising organizations take basic steps including code encryption, enforcement of code-change and access controls, reading their log monitors and denying access to non-project staff, such as systems administrators.

"Organizations need to recognize the software they develop is crucial - they need to restrict access and protect systems from administrators who don't need access to that information," Software Engineering Institute business manager Joseph McLeod told the RSA security conference in San Francisco today. "Things like encryption can be used to protect that IP."

Sharing its insights from 245 cases since 1996 on internal attack, CERT told RSA a third of IT attacks come from inside organizations - and that they can inflict as much damage as external hackers in terms of stolen IP, financial loss, and even threats to personal safety.

CERT calls this "IT sabotage" - attacks by disgruntled employees intended to harm an organization directly, by preventing its ability to trade or by causing embarrassment through activities like forwarding private information to customers, competitors or employees, or by binging down a web site.

These differ to attacks from managers stealing trade secrets to enrich themselves and from employees accessing things like customer records to, for example, sell information like social security numbers to identity thieves.

What constitutes a disgruntled employee? Somebody whose expectations have not been meet, such as being passed over for a promotion, or getting let go.

Saboteurs span the ages, from 17 to 70, unlike those simply stealing trade secrets or social security numbers who average out in their mid-30s. "Who'd picture a 60 year old trying to do IT sabotage," Dawn Cappelli, a senior member of SEI technical staff, mused to Reg Dev, after her joint presentation to RSA.

And while the signs of a disgruntled staffer - such as slipping personal hygiene, increased absenteeism, or violent and aggressive behavior - are easy to identify and can be acted on, the tell-tale technical signs often get overlooked by organizations.

These include the insertion of back-door accounts into systems, and the creation of malicious code followed by its testing, installation, downloading and execution.

The most convenient channels to launch what CERT calls "technically sophisticated" attacks are the exploitation of access paths such as those back doors, use of shared or stolen passwords, planting logic bombs, and exploitation of colleagues' machines that have been left running.

Not all attacks are purely digital. Carnegie Mellon recounted the tale of one staffer who stole a contractor's IT badge and used it to access a restricted building, and take down a 9/11 emergency phone number/address look-up system in an attempt to impress a new boss starting work the next day.

For more on the insider threat to software development, see CERT's podcast here

Designing a Defense for Mobile Applications

More from The Register

next story
Mozilla fixes CRITICAL security holes in Firefox, urges v31 upgrade
Misc memory hazards 'could be exploited' - and guess what, one's a Javascript vuln
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Don't look, Snowden: Security biz chases Tails with zero-day flaws alert
Exodus vows not to sell secrets of whistleblower's favorite OS
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
Researcher sat on critical IE bugs for THREE YEARS
VUPEN waited for Pwn2Own cash while IE's sandbox leaked
Four fake Google haxbots hit YOUR WEBSITE every day
Goog the perfect ruse to slip into SEO orfice
prev story

Whitepapers

Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.