| Perfect Storm: The Insider, Naivety, and Hostility |
| Full text |
Html
(27 KB),
Pdf
(956 KB)
|
Source
|
Queue
archive
Volume 2 , Issue 4 (June 2004)
table of contents
Surviving Network Attacks
FEATURE: Q focus: Security
table of contents
Pages: 58 - 65
Year of Publication: 2004
ISSN:1542-7730
|
|
Authors
|
|
| Publisher |
|
| Bibliometrics |
Downloads (6 Weeks): 97, Downloads (12 Months): 172, Citation Count: 0
|
|
|
ABSTRACT
Every year corporations and government installations spend
millions of dollars fortifying their network infrastructures.
Firewalls, intrusion detection systems, and antivirus products
stand guard at network boundaries, and individuals monitor
countless logs and sensors for even the subtlest hints of network
penetration. Vendors and IT managers have focused on keeping the
wily hacker outside the network perimeter, but very few
technological measures exist to guard against insidersthose
entities that operate inside the fortified network boundary. The
2002 CSI/FBI survey estimates that 70 percent of successful attacks
come from the inside. Several other estimates place those numbers
even higher.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
1. Power, R. 2002 CSI/FBI computer crime and security survey. Computer Security Issues and Trends VIII, 1 (Spring 2002).
|
| |
2
|
2. Hayden, M. V. The Insider Threat to U. S. Government Information Systems. Report from NSTISSAM INFOSEC /1-99, July 1999.
|
| |
3
|
3. Ferrie, P., and Lee, T. Analysis of W32.Mydoom.A@mm; http://securityresponse.symantec.com/avcenter/venc/ data/w32.novarg.a@mm.html.
|
| |
4
|
4. Bridwell, L., and Tippett, P. ICSA Labs 7th Annual Computer Virus Prevalence Survey 2001. ICSA Labs, 2001.
|
| |
5
|
5. See, for example, Microsoft Security Bulletin MS03- 050, Vulnerability in Microsoft Word and Microsoft Excel Could Allow Arbitrary Code To Run: http: //www.microsoft.com/technet/security/bulletin/MS03- 050.mspx; or MS03-035, Flaws in Microsoft Word Could Enable Macros To Run Automatically: http://www.microsoft.com/technet/security/bulletin/ MS03-035.mspx.
|
| |
6
|
6. Dos Santos, A., Vigna, G., and Kemmerer, R. Security testing of the online banking service of a large international bank. Proceedings of the First Workshop on Security and Privacy in E-Commerce (Nov. 2000).
|
| |
7
|
7. Sophos Corporation. Top ten viruses reported to Sophos in 2003; http://www.sophos.com/virusinfo/ topten/200312summary.html.
|
REVIEW
"George Michael White : Reviewer"
Troy was taken from the inside. The story of the Trojan horse, known to us for more then two millennia, has endured for a long time. It tells of a universal threat, that of attack from inside the walls. Network administrators have long been
more...
Peer to Peer - Readers of this Article have also read:
-
Data structures for quadtree approximation and compression
Communications of the ACM
28, 9
Hanan Samet
-
A hierarchical single-key-lock access control using the Chinese remainder theorem
Proceedings of the 1992 ACM/SIGAPP Symposium on Applied computing
Kim S. Lee
, Huizhu Lu
, D. D. Fisher
-
The GemStone object database management system
Communications of the ACM
34, 10
Paul Butterworth
, Allen Otis
, Jacob Stein
-
Putting innovation to work: adoption strategies for multimedia communication systems
Communications of the ACM
34, 12
Ellen Francik
, Susan Ehrlich Rudman
, Donna Cooper
, Stephen Levine
-
An intelligent component database for behavioral synthesis
Proceedings of the 27th ACM/IEEE Design Automation Conference on
Gwo-Dong Chen
, Daniel D. Gajski
|