DocuCrunch.com » Hackers more sophisticated than ever: Can IT keep up?

Hackers more sophisticated than ever: Can IT keep up?

May 4, 2010 by Steve Hannaford
Posted in: Security, Special Report

hacker

The notion that cyber attacks on your business were coming from attention-craving mischief-makers working in their parents’ basements is slow to die. But today’s cybercriminals are a highly sophisticated bunch.

The reality is that the most pernicious attacks on your system are coming from determined criminals with state-of-the-art tools, clear targets and, almost certainly, more cutting-edge software expertise than your company can afford. These criminals are feeding a growing global demand for black-market information, and they are richly rewarded for it.

Take for example the recent Hydraq attack (alias Aurora, Microsoft IE Vulnerability, or Google Attacks), which hit the business world a few months ago.

The software installs a Trojan horse program on a computer and then “attempts to make contact with command and control servers in order to receive instructions and to upload any information that it may have collected. This type of attack is often called an advanced persistent threat because of the sophistication and persistence of the attack within a business.”

The software can capture keystrokes, upload files and replicate itself across the network. It is, according to Francis deSouza, Senior Vice President, Enterprise Security Group at Symantec, part of an increasing pattern of “well-organized attacks that leverage insidious malware and social engineering tactics to target key individuals and penetrate corporate networks.”

If your company has any information that is mission-critical, sensitive or confidential (and few companies larger than a nail salon don’t handle data that fits this description), it is of interest to someone who might be paying for access to it.

And while IT security companies like Symantec, McAfee, and Sophos come out with patches to plug these holes as fast as they can, and even Microsoft is getting better at sending out yet another system update, a good number of companies have already been ripped off, and the cybercriminals are already coming up with a new means of defeating the new obstacles

The organized cybercriminals, according to Symantec’s deSouza, use a four-step process, often having separate expert teams for each step of the attack:

  1. an incursion phase, where access is gained to a company’s network through a variety of malware including e-mail attachments
  2. a discovery phase, where the topography of the corporate network is mapped out and the locations of key asset are identified
  3. a capture phase, where “they find and seize information that has a black market value, such as credit card information, identities, customer or patient records, intellectual property,” and so on, and
  4. An exfiltration phase, where the data is moved off the network into the hands of the criminals.

All of this can (and often does) take place without any sign that the intrusion is happening. With the criminal’s team approach and a clear breakdown of roles, the typical company network hasn’t a chance of even knowing that its pockets have been picked.

If your company hasn’t upgraded its security plan within the last year, it is getting more and more vulnerable. Yes apply the patches and updates (though for many companies even that is a low priority), but the more valuable the data the more you need to go beyond the basic steps.

  • Share/Bookmark

DocuCrunch.com delivers the latest IT and Imaging news once a week to the inboxes of over 200,000 IT and Imaging professionals.

Click here to sign up and start your FREE subscription to DocuCrunch!

Tags: , , ,


Comments are closed.


advertisement


Whitepapers

  • How to Select a Web Host
    November 27, 2011 by marketing

    Creating a new website?  Not sure how to choose from among all the options?  Need shared hosting, small business hosting, or VPS hosting?  Lots of email accounts? 5-star reliability rating? Fortunately, there’s information available to help. The Best Web Hosts is great resource that will help you select the best web hosting company. It features reviews, rankings, and definitions that can help make your job of selecting a new web host more effective.

  • SMART Steps Towards Workload Automation
    January 19, 2010 by Luke Marchie

    Consolidating job scheduling into a single, comprehensive workload automation solution is a critical first step to effective Workload Automation (WLA).

    Download the free whitepaper here! More…

  • Identifying and Thwarting Malicious Intrusions
    January 12, 2010 by Luke Marchie

    Identifying and Thwarting Malicious Intrusions

    The phenomenal growth in social media has opened the door for all new malicious intrusions from gangs of cyber criminals. Utilizing the trusted relationships in social networking and benefiting from immature security and content controls, hackers are seeing increased performance in their attacks.

    Download the free whitepaper here More…

  • The Security Issues with Web 2.0
    January 12, 2010 by Luke Marchie

    The collaborative benefits of Web 2.0 technologies have fueled rapid growth in online consumer markets and now are being adopted by businesses worldwide. With these technologies come new types of attack vectors.

    Download the free whitepaper here

    More…

  • Network-Critical Physical Infrastructure: Optimizing Business Value
    December 29, 2009 by Luke Marchie

    To stay competitive in today’s rapidly changing business world, companies must update the way they view the value of their investment in Network-Critical Physical Infrastructure (NCPI). No longer are simple availability and upfront costs sufficient to make adequate business decisions. Agility, or business flexibility, and low total cost of ownership have become equally important to companies that will succeed in a global, ever-changing marketplace.

    Download the free whitepaper here! More…

  • The New World of eCrime: Targeted Brand Attacks and How to Combat Them
    December 26, 2009 by Luke Marchie

    Nothing is more valuable to a business than its reputation. That is why brand attacks, which leverage a company’s valuable brand for nefarious purposes, must be battled on every possible front. Brand attacks are the new form of eCrime, and they’re being launched with new and rapidly evolving exploits, including phishing and—most recently—malware.

    Download the free whitepaper here! More…

  • DDoS: The Mother of All Cyber Threats
    December 16, 2009 by Luke Marchie

    DDoS: The Mother of All Cyber Threats

    Don’t wait until your business is targeted. A Forrester Consulting study commissioned by VeriSign revealed that nearly 75 percent of the 400 study respondents have experienced one or more DDoS attacks in the past year. Yet, most e-commerce businesses are not prepared for a large-scale DDoS attack. Could your business afford three or more hours of downtime? Avoid that revenue loss by registering for this free white paper

    Click here to download the free white paper More…

  • View more offers


    Quick Vote

    • Does your office have a color printer or copier?

      • Yes (75%, 3 Votes)
      • We're looking into buying one (25%, 1 Votes)
      • No (0%, 0 Votes)

      Total Voters: 4

      Loading ... Loading ...

  • advertisement