home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers









Intrusio n Detection Provides A Pound Of Prevention


Intruder Detection Questions & Answers

If some or all of this intrusion detection information is new to you, you're probably fairly concerned about your own network. But remember folks, we're the good guys. People frequently ask us questions about the risk of such an attack happening to them. What follows is our advice to you.

Q: What skill set is required to carry out a successful attack against my organization?

A: It depends on how quickly the attackers need results, and of course, what they're aft er. A team of skilled attackers may accomplish their goals in three to four days. A lone attacker with rudimentary skills may require several weeks or more. Even beginners will eventually get to their target, provided they are not discovered in the process. You may even have random joy riders, who quickly gain access to one system in your organization, simply to use it as a jumping off point to attack completely unrelated entities on the network. They collect systems here and there, much like collecting baseball cards or stamps. They have no real goal, other than to collect.

Q: Does the size of my network affect the chances of a successful attack?

A: Yes, chances for success are a function of the size of an organization's network. The bigger, the better. There are more things to misconfigure and it's harder to monitor and control. Although there is the possibility of a small business employing not adept or poorly trained individuals, even a large, well-staffed organization will lose by falling victim to its own interdepartmental politics and poor communicat ion. Think of the tale, Jack and the Beanstalk: "The bigger they are, the harder they fall."

Q: I'm concerned about all these direct network connections we're putting up to our business partners. Should I be worried?

A: This is an element of network security that we don't test for reasons of defined scope. We are limited to our clients networks and computing resources and don't have permission to launch a proxy attack against their business partners' assets. On several occasions we have seen unrestricted network access to and from other organizations partnering with our client. In a real-life attack scenario, the attackers may decide that a direct attack is too difficult. Using publicly available sources, they would determine who the target organization had network connections to. They would then launch an attack against the business partner with the sole intent of using the trusted network connection for the attack against the intended targ et. These connections are almost never firewalled. Soun ds far-fetched? Think again, it's already being done.



For the Side Bar on
Test Systems And Tools

Specific System Attack


Updated July 31, 1997





Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



InformationWeek Business Technology Network
InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo JitterPlug Into The Cloud
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business ExpoSoftware ConferenceCSI - Computer Security Institute
Black HatGTECEnergy CampMashup CampStartup Camp
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet EvolutionPyramid Research
Heavy ReadingLight Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
space
Microsoft Technology Network
MSDN MagazineTechNetThe Architecture Journal
space


App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2009  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights