Feeds

Old people can sabotage software too

Games insiders play

New hybrid storage solutions

RSA Software teams must act to protect systems and development projects from revenge attacks by disgruntled current and former employees.

So says Carnegie Mellon Software Engineering Institute's CERT, which is advising organizations take basic steps including code encryption, enforcement of code-change and access controls, reading their log monitors and denying access to non-project staff, such as systems administrators.

"Organizations need to recognize the software they develop is crucial - they need to restrict access and protect systems from administrators who don't need access to that information," Software Engineering Institute business manager Joseph McLeod told the RSA security conference in San Francisco today. "Things like encryption can be used to protect that IP."

Sharing its insights from 245 cases since 1996 on internal attack, CERT told RSA a third of IT attacks come from inside organizations - and that they can inflict as much damage as external hackers in terms of stolen IP, financial loss, and even threats to personal safety.

CERT calls this "IT sabotage" - attacks by disgruntled employees intended to harm an organization directly, by preventing its ability to trade or by causing embarrassment through activities like forwarding private information to customers, competitors or employees, or by binging down a web site.

These differ to attacks from managers stealing trade secrets to enrich themselves and from employees accessing things like customer records to, for example, sell information like social security numbers to identity thieves.

What constitutes a disgruntled employee? Somebody whose expectations have not been meet, such as being passed over for a promotion, or getting let go.

Saboteurs span the ages, from 17 to 70, unlike those simply stealing trade secrets or social security numbers who average out in their mid-30s. "Who'd picture a 60 year old trying to do IT sabotage," Dawn Cappelli, a senior member of SEI technical staff, mused to Reg Dev, after her joint presentation to RSA.

And while the signs of a disgruntled staffer - such as slipping personal hygiene, increased absenteeism, or violent and aggressive behavior - are easy to identify and can be acted on, the tell-tale technical signs often get overlooked by organizations.

These include the insertion of back-door accounts into systems, and the creation of malicious code followed by its testing, installation, downloading and execution.

The most convenient channels to launch what CERT calls "technically sophisticated" attacks are the exploitation of access paths such as those back doors, use of shared or stolen passwords, planting logic bombs, and exploitation of colleagues' machines that have been left running.

Not all attacks are purely digital. Carnegie Mellon recounted the tale of one staffer who stole a contractor's IT badge and used it to access a restricted building, and take down a 9/11 emergency phone number/address look-up system in an attempt to impress a new boss starting work the next day.

For more on the insider threat to software development, see CERT's podcast here

Secure remote control for conventional and virtual desktops

More from The Register

next story
Leak of '5 MEELLLION Gmail passwords' creates security flap
You should be OK if you're not using ANCIENT password
Google recommends pronounceable passwords
Super Chrome goes into battle with Mr Mxyzptlk
Reddit wipes clean leaked celeb nudie pics, tells users to zip it
Now we've had all THAT TRAFFIC, we 'deplore' this theft
Enigmail PGP plugin forgets to encrypt mail sent as blind copies
User now 'waiting for the bad guys come and get me with their water-boards'
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.