SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Hacking and Viruses

Websense advises IT managers to think like criminals

Websense advises IT managers to think like criminals

By:  Greg Enright  On: 12 Nov 2007 For: ComputerWorld Canada Creator

The hacker community is becoming much better organized and often its goal is to find sensitive data without prospective targets discovering there was a security breach. How to protect yourself

Where the malicious hacker community was once dominated by glory-seekers craving the notoriety associated with bringing a big Web site to its knees, the community is quickly evolving into a slick network of organized groups intent on exploiting the Internet's weaknesses for ongoing financial gain.

"The hacker-cracker community has been criminalized and very much focused on making money — and there is a lot of money to be made in a lot of different ways," says IDC security analyst Chris Christiansen. Information, he points out, is the new currency because it can be traded throughout the world.

"There are sites where you can buy zero-day exploits for targeted attacks, and there are sites where you can rent botnets. This is a business, in terms of products and services, in terms of support and in terms of how it's organized."

Further highlighting the similarities between this modern organized style of online pilfering and legitimate businesses is the degree of interaction between many of the grifting groups, adds Christiansen.

"People work in a loose association of partnerships that, by the way, is surprisingly well-maintained and fairly disciplined. It doesn’t operate in isolation the way many people think," says the Framingham, Mass.-based industry observer. "They communicate with each other, they feed each other information, they trade information and they pay one another in a variety of forms."

According to Fiaaz Walji, Canadian country manager for security software vendor Websense Inc., many of these organized units are drawing their computing prowess from young minds looking for quick and handsome paycheques.

"FBI reports (indicate) that organized crime will now go and recruit students," Walji says. "If you think of economies that are faltering, be it Russia or whatever, when these super-smart guys are approached with an offer for financial gain, it's hard for them to resist. Organized crime might outsource it to four or five hackers or they bring them into their own organization."

Where the glory-seeking hacker is typically looking to get noticed through his actions, this modern breed of cybercriminal is instead looking for complete anonymity.

"You don’t want to bring down a target, or (have anyone) know about it," points out Christiansen. "If you do this really carefully, you would want [victim organizations] to be largely unaffected by the attack. The idea is, if you're stealing information, wouldn’t it be nice to steal that for months, years, possibly even decades?"

Christiansen adds that part of the attraction for these groups is the ease with which their nefarious goals can be realized. "It's relatively low-risk and it's easy."

It's low-risk in part because there are so few ways for authorities to combat it. Says Walji: "The Internet is very conducive to their type of crime because there are no borders. Laws are very vague in that if you originate in one country, exploit someone in another country and then sell the data to someone in a third country, what jurisdiction does that fall under?"


Sign up for our Newsletters












Print |  Views: 1389   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Greg Enright Greg Enright is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Mafiaboy to headline IT 360
Mafiaboy to headline IT 360As a 15-year-old, he brought down some of the highest profile sites on the Web. Eight months of detention and eight years of silence later, Michael Calce discusses what the good guys can learn from the black hats
Engineer questions security of antivirus software
Engineer questions security of antivirus softwareThierry Zoller, a German based security engineer, is questioning if the software we're using to protect ourselves from online attacks is becoming a liability. For the past two years, Zoller, a security engineer for n.runs AG, has taken a close look at the way antivirus software inspects e-mail traffic.
Germany passes antihacking law
Germany passes antihacking lawHackers may want to avoid Germany, after the approval of a law that makes their activity a punishable crime. The legislation, which the German government proposed earlier last year and approved Friday with no changes, aims to crack down on the sharp rise in computer attacks in the public and private sectors.
BlackHat USA 2008 - Day 2 Review
today was the second and final day of the blackhat usa briefings. a lot of great content was presented today. much like yesterday we’ve included some highlevel comments on the various presentations that tadd and i attended. we will be attending defcon over the weekend and tying that into one final posting next week. what follows is our summary.
blog comments powered by Disqus