Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity
    • IT Management
    • Networking

    WikiLeaks Controvesy Highlights Insider Threats

    Written by

    Brian Prince
    Published November 30, 2010
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      At the center of the WikiLeaks controversy is U.S. Army Private First Class Bradley Manning, the man suspected of having passed the whistle-blower Website a massive collection of U.S. embassy cables.

      Manning has been in military custody for the past several months with charges of transferring classified information to his personal computer and passing it on to an unauthorized source hanging over his head. But it was not monitoring software that exposed Manning; in fact it was an informant, former hacker Adrian Lamo, who Manning allegedly bragged to via instant message.

      The situation underscores the problems surrounding access controls and malicious insiders, and it has prompted the U.S. Office of Management and Budget (OMB) to issue amemorandum (PDF) to the heads of the country’s executive departments and agencies requiring them to review “the agency’s configuration of classified government systems to ensure that users do not have broader access than is necessary to do their jobs effectively, as well as implementation of restrictions on usage of, and removable media capabilities from, classified government computer networks.”

      In a chat log between Lamo and Manning published by Wired magazine, Manning reportedly wrote that he would come in with a CD labeled “with something like ‘Lady Gaga’ … erase the music … then write a compressed split file.”

      The OMB memo was not the first time government officials have taken a hard look at removable media. For example, the military banned USB devices temporarily in 2008 in response to malware attacks. But banning removable media and storage devices will not deter someone from using them if that policy is not enforceable, said Michael Maloof, CTO at TriGeo Network Security.

      “Real-time monitoring and blocking is not only possible, it’s essential, and it’s the only way to ensure that sensitive data is never transferred to an unauthorized device,” he said.

      From an attack perspective, personal, portable devices are far too easy to hide in a bag or pocket, noted Hugh Garber, product marketing specialist at Ipswitch File Transfer.

      “Portable devices increase risk,” he said. “Easily lost or stolen USB drives, external hard drives, smartphones and even using personal e-mail accounts can increase security risk, compliance risk and data breach risk. Portable personal devices relinquish visibility, [the ability to be audited] and compliance because they aren’t being integrated into overall file transfer monitoring or reporting.”

      Controlling data leaks also means managing access.

      “Simply put, organizations must ask, ‘What does this person need to accomplish their stated mandate, and nothing more?’ and then again deploy the right management tools to ensure they have what they need while adhering to the organization’s policies. Identity is again the key to making this work well,” said Grant Ho, director of solutions and product marketing for End User Computing Solutions at Novell.

      In its latest data breach report, Verizon reported that roughly 48 percent of data breaches during 2009 involved someone internal maliciously abusing his or her right to access corporate information. Technology aside, identifying people in an organization who may leak or steal confidential data is far from an exact science.

      “This is one of the biggest problems … there isn’t a profile or common traits [of malicious insiders],” said Ho. “In fact, sometimes people gain access to information without knowing that they shouldn’t. There are times when you should be more careful, such as if an employee is laid off or fired. Disgruntled employees will look for ways to compromise data. [But] profiling this is incredibly difficult.”

      “There’s a fine line between trusted insider and malicious insider,” added Jack Hembrough, CEO of VaporStream. “System Administrator is a powerful position, and someone’s got to occupy it. Rather than trying to identify who might ‘go bad,’ I think it’s more productive to help honest people stay honest by managing what the System Administrator can do.”

      Brian Prince
      Brian Prince

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.