Published on Security Management (http://www.securitymanagement.com)
When Insiders Attack.
By
August 2005



    
Print Edition Only: 
No
Beyond Print?: 
No
Weight: 
0
Issue: 
August 2005 [1]
Teaser: 

The study, conducted by the U.S. Secret Service and Carnegie Mellon University’s CERT/CC, found that more than 60 percent of the 49 attacks examined in the study were carried out with “relatively unsophisticated methods of attack,” such as social engineering; only 39 percent used a toolkit or other program designed to cause havoc.

A study based on interviews with insiders who had been apprehended after attacks on company networks found that systems were vulnerable to the simplest exploits.

The study, conducted by the U.S. Secret Service and Carnegie Mellon University’s CERT/CC, found that more than 60 percent of the 49 attacks examined in the study were carried out with “relatively unsophisticated methods of attack,” such as social engineering; only 39 percent used a toolkit or other program designed to cause havoc.

More than a quarter of the insiders had been terminated or already resigned when the attacks took place, but their employers did not disable their access to the network. And more than half of the attacks were conducted remotely, with a similar percentage taking place after hours or on weekends.

Who were these attackers? Most were former employees or contractors who had been fired (48 percent); and while most (86 percent) had technical positions such as system administrator or programmers, 10 percent had professional positions such as editor, manager, or auditor. Almost a third of those insiders had an arrest history, typically for nonviolent, alcohol-related, or drug-related offenses.

The study found that 90 percent of these insiders faced criminal charges, most often federal charges; 83 percent were found guilty by trial or by plea. Forty-two percent of the offenders went to prison from 2 to 41 months, and 59 percent were ordered to pay restitution ranging from $100 to $2 million.

Who did victims call when they discovered a problem? Victimized organizations contacted local police departments or local prosecutor’s offices at about the same rate as they did federal law enforcement agencies or U.S. attorney’s offices.

@   The study is called Insider Threat Study: Computer System Sabotage in Critical Infrastructure Sectors. It is available at SM Online.

Related Resources: 
AttachmentSize
insider_report0805.pdf [2]163.26 KB

Comments


Security Management is the award-winning publication of ASIS International, the preeminent international
organization for security professionals, with more than 35,000 members worldwide.

ASIS International, Inc. Worldwide Headquarters USA, 1625 Prince Street, Alexandria, Virginia 22314-2818
703-519-6200 | fax 703-519-6299 | www.asisonline.org
ASIS
Copyright © 2008, Security Management

Powered by: Phase2 Technology

Source URL: http://www.securitymanagement.com/article/when-insiders-attack-0

Links:
[1] http://www.securitymanagement.com/magazine/2005/08
[2] http://www.securitymanagement.com/sites/securitymanagement.com/files/insider_report0805_0.pdf