Tampilkan postingan dengan label information security. Tampilkan semua postingan
Tampilkan postingan dengan label information security. Tampilkan semua postingan

Rabu, 14 September 2011

How hackers find their targets

experian.com

The rash of large-scale data breaches in the news this year begs many questions, one of which is this: how do hackers select their victims?

The answer: research.

Hackers do their homework; in fact, an actual hack typically takes place only after many hours of first studying the target.

Here’s an inside look at a hacker in action:


  1. Using search queries through such resources as Google and job sites, the hacker creates an initial map of the target’s vulnerabilities. For example, job sites can offer a wealth of information such as hardware and software platform usage, including specific versions and its use within the enterprise.
  2. The hacker fills out the map with a complete intelligence database on your company, perhaps using public sources such as government databases, financial filings and court records. Attackers want to understand such details as how much you spend on security each year, other breaches you’ve suffered, and whether you’re using LDAP or federated authentication systems.
  3. The hacker tries to identify the person in charge of your security efforts. As they research your Chief Security Officer or Chief Intelligence Security Officer (who they report to, conferences attended, talks given, media interviews, etc.) hackers can get a sense of whether this person is a political player or a security architect, and can infer the target’s philosophical stance on security and where they’re spending time and attention within the enterprise.
More...

Rabu, 17 Agustus 2011

Corporate cybercrime tops boardroom agenda

freshbusinessthinking.com



High profile corporate cybercrime is putting information security on boardroom agendas around the world, a global survey revealed on Wednesday.



The need for increased measures to protect against corporate espionage and network hacking, the accidental or deliberate leaking of corporate data, and the loss or theft of company laptops, has never been so high, company bosses told the British Standards Institution (BSI), the leading business service for the development of standards, in a survey.



According to the research, which analyses responses from 645 businesses, risk of corporate data leaks is a key concern. Two thirds (64%) of the surveyed businesses that have implemented ISO 27001 (an information security management system) cited this as the most important driving force behind adopting the information security standard.



In addition to risk, the BSI research also shows that 72% of businesses are worried about the financial damage of cybercrime.



More...

Related Posts Plugin for WordPress, Blogger...