Antivirus, NIDPS, WAF, NAC, DLP, IP Firewalls, Web Proxies, etc. are all great controls and protect against most known and some unknown attack vectors and for the most part they work. What scares me and keeps me up at night are the -1 day attacks (less than zero) that will pass by all controls. This story in USA Today got me thinking about how easy it is for determined attackers to slip right by all my controls and begin pumping data out of my network. From the article:
The virus swiftly located — and infected — some 300 other workstation PCs, silently copying the contents of each computer's MyDocuments folder. It transmitted the data across the Internet to a gang of thieves operating out of Turkey.They infected system zero by posting an innocent-looking link on a trusted employee-only message board. Reading articles and hearing horror stories from colleagues about the threats they didn't know about until after the damage was done is what keeps me up at night. The stuff I know about? I have lots of toys for that stuff. :)
Related Articles
- 11 charged with massive ID theft
- Auto Parts Retailer Notifies Customers of Network Breach
- University of Florida discloses patient-record data breach
- The most insidious IT security risk
- A Huge Cache of Stolen Financial Data
- Express Scripts Clients Receive Threats To Release Data
- 5 ways insiders exploit your network
1 comment:
Interesting article and frustratingly, I think the scenario you write about happens more than we like to think.
I recently posted the following at my blog that offers some free resources to IT professionals.
As an ongoing effort to continually provide free resources, there are three new ones listed below. Primarily intended for IT-Professionals, if you are engaged in computer security these e-books are provided at no cost to you.
The 7 Things that IT Security Professionals MUST KNOW!
Link: http://homelandsecuritygroup.tradepub.com/free/w_eeye05/
Vulnerability Management for Dummies
Link: http://homelandsecuritygroup.tradepub.com/free/w_qa18/
60-Day Trial of Microsoft Office Project
Link: http://homelandsecuritygroup.tradepub.com/free/w_msf107/
Hopefully you folks may find these of interest. There's no cost...but good info all the same.
Anthony "Tony" M. Davis
Bestselling Author: “Terrorism and the Maritime Transportation System”
Post a Comment