Computerworld
Quick Menu
Search



Ads by TechWords

See your link here


Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Networking
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
Computerworld 2007Subscribe to Computerworld
40 years of the most authoritative source of news and information for IT leaders.

5 ways insiders exploit your network

Internal theft and sabotage can hit companies hard in many ways


Active Comments

Gaurav says: The article does raise a very valid concern about the users inside an organization being the ultimate threats. More dangerous...
Anonymous says: As HS Thompson might say, The problem here is that you're not sharing what you're smoking. This list is worse...


May 8, 2008 (Network World) Cox Communications employee William Bryant recently pleaded guilty to information technology sabotage, having caused the loss of computer, telecommunications and emergency 911 services for thousands of Cox's business and residential customers throughout Dallas, Las Vegas, New Orleans and Baton Rouge. Bryant faces a 10-year jail sentence and a $250,000 fine, but the future is less certain for Cox. Although services were fully restored, the incident's effect on Cox's reputation has yet to be determined.

The Cox story -- along with recently publicized incidents at NASA, Accenture, Gap and Medco -- serves as a harsh reminder that insiders represent a common and often misunderstood threat. Data theft and sabotage can result in hard costs, compliance-related problems, legal fees, productivity loss and, possibly most costly, loss of reputation.

Insider threats are up 17%, according to the latest Computer Security Institute survey (a trend echoed by recent surveys by Deloitte and by CSO magazine). As IT and communication systems grow in complexity, so too do the numbers of employees, contractors and managed service providers required to maintain them. The spike in threats is not surprising given the often unfettered and unmonitored access these insiders have to critical corporate networks.

It should be clear that companies need to monitor insiders as aggressively as they do outsiders. However, policing insiders can prove challenging given the privileged access they require to do their jobs. Here are the five most common methods insiders use to access network resources and simple measures enterprise IT can take to protect against the implied threats.

1. Modems. A lack of central management combined with easy-to-guess static passwords make modems an ideal entry point for insiders with detailed knowledge of a network. Many companies have tried to address this challenge by simply unplugging modems until needed. However, unplugging modems makes it impossible to use them for their intended purpose, namely remotely restoring critical systems in times of emergency or outage.

Given that modems are a necessity, enterprises must extend the same security and identity confirmation measures to modems that they do to other remote-network entry points. Extending corporate two-factor authentication measures to modems or replacing legacy modems with newer, more secure models with embedded multifactor authentication can provide appropriate and cost-effective protection.

2. Open file transfer. Most organizations use open file transfer to patch network infrastructure. Internal technicians and vendors use this poorly secured, unrestricted access to troubleshoot, apply appropriate fixes and correct problems. However, they also can misuse this freedom to change files, remove critical components or disrupt systems, resulting in nonoperational systems, Web site defacements, data theft and other damaging situations.


Reprinted with permission from

For more information about enterprise networking, go to NetworkWorld.com
Story copyright 2008 Network World, Inc. All rights reserved.

What People Are Saying

XenServer FREE trial
XenServer FREE trial
Citrix XenServer is the simplest and most effective way to virtualize and provision servers. XenServer combines comprehensive server virtualization capabilities with unparalleled scalability, performance, economics, and ease-of-use. Based on the open source Xen hypervisor, XenServer delivers fast performance, easy management, and advanced features such as live migration.

Request free trial now

Your Say
Chrome a Windows killer?
Anonymous wrote: Having to be connected to use apps that are not inherently dependent upon being connected is a liability...
[read the story | have your say]
Hot topics now:
White Papers
Accelerate your pursuit of perfection
For almost 80 years, Kodak has been helping banks, insurance companies, healthcare providers, government agencies and other businesses produce billions of document images. So Kodak is uniquely positioned to know and deliver–what customers want: easy-to-use scanners that output the best possible image quality.
Download this white paper now! 
TODAY'S TOP BLOG
Patrick Thibodeau:
Satellite images of U.S military bases
Which is more important? Helping terrorists or protecting military bases? Answer: protecting Web 2.0 ... [more]
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
The 2008 ERP in Manufacturing Benchmark Report Summary
IronPort Web Reputation Filters Tech Note
Designed to Manage Lean Principles
View more whitepapers 
 

Keys to Microsoft application acceleration: advances in delivery systems
Simply designing a data center that only deploys more servers, more storage, and more devices significantly increases network complexity and cost. You can now ensure significantly faster access to the Microsoft applications your users depend on.

Download this whitepaper 
Next Gen Load Balancing: 8 Things You Need to Handle Today's Network Traffic
Learn how you can replace your aging load balancer with a true web application delivery appliance that provides 100% availability through full Layer 7 awareness and intelligent traffic management and delivers web apps with the highest performance and security possible.

Download this white paper 
Constellation Brands Case Study
Learn why a $6.5 billion international producer and marketer of alcoholic beverages chose Citrix NetScaler to increase Web app performance and ensure high availability of global intranet and public Web sites.

Download this case study 
Welch's Case Study
Learn why a large US food processor chose Citrix NetScaler to securely deliver a new Oracle ERP solution to external partners and remote users. You'll learn how Welch's was able to add 250 new users without expanding their IT staff or taxing the availability of their network resources.

Download this case study