Anticipating Threats Massachusetts

CIOs can no longer rely solely on security updates and patch management companies to keep their businesses safe from hackers and criminals. Recent attacks to computer networks have shown how dangerous today's security threats can be. When MyDoom brought down the servers of software company SCO earlier this year, the damage was so extensive and expensive that the firm offered a $250,000 reward to anyone who could catch the virus creator. The SQL Slammer worm that hit hard in January caused airplanes to be grounded and ATM machines to malfunction, all of which added up to a reported $1 billion price tag. Even Internet businesses -- companies that should be in the know, such as eBay and America Online -- have fallen prey to hacks and malware (short for "malicious software").

Local Companies

Centro de Internet J Y R
809-725-5530
calle D no. 14 Ens. 27 de Febrero.
San Francisco de Macoris, MA
Excalibur Consulting Inc
(978) 664-0862
350 Park St Ste 107
North Reading, MA
Howard Tabor Associates Inc
(413) 567-0882
25 Harwich Rd
Longmeadow, MA
John Snow Inc
(617) 482-9485
44 Farnsworth St
Boston, MA
Bay State Corporate Services Inc
(617) 742-8484
6 Beacon St
Boston, MA
Stone and Company
(781) 383-8383
164 Chief Justice Cushin
Cohasset, MA
Measurement Dimensions Inc
(781) 631-1100
212 Humphrey St Ste 201
Marblehead, MA
West Falmouth Associates
(508) 495-0738
Falmouth, MA
Mass Businessman
(781) 228-2100
135 Wood Rd
Braintree, MA
Invest Northern Ireland
(617) 266-8839
545 Boylston St Lbby 2
Boston, MA


Anticipating Threats



By Lauren Barack

CIOs can no longer rely solely on security updates and patch management companies to keep their businesses safe from hackers and criminals. Recent attacks to computer networks have shown how dangerous today's security threats can be. When MyDoom brought down the servers of software company SCO earlier this year, the damage was so extensive and expensive that the firm offered a $250,000 reward to anyone who could catch the virus creator. The SQL Slammer worm that hit hard in January caused airplanes to be grounded and ATM machines to malfunction, all of which added up to a reported $1 billion price tag. Even Internet businesses -- companies that should be in the know, such as eBay and America Online -- have fallen prey to hacks and malware (short for "malicious software").

The onslaught of threats continues, and groups that track attacks made across the Internet are finding these dangers on the rise. Recently, the SANS Institute's Internet Storm Center, which monitors the activity and traffic on the Internet, noted that unprotected servers were getting hacked approximately every 13 minutes. In fact, about 80 percent of the activity on the Internet is taken up every day by viruses, worms, spyware and other forms of malware, according to Peter Cochrane, a co-founder of technology consultancy firm ConceptLabs.  Experts believe so-called "zero-day" threats -- a virus or worm that hits the Internet within minutes of the announcement of a known software weakness -- are a very likely danger.

CIOs who rely on a reactive approach are potentially endangering their company's data. This wait-and-see mind-set gives attackers the edge. In some cases, companies literally pay the price, as they become victims of hacker extortion. For example, a hacker will attack a company with a DDoS (distributed denial-of-service attack), and then threaten to do it again if not paid. At least six to seven thousand companies are paying online extortion demands, according to Alan Paller, director of research of the SANS Institute. "[The hackers'] motivation is money and extortion," agrees Lance Spitzner, a founding member of The Honeynet Project, a five-year-old non-profit hacker research group. "The easiest way for them to make money is to threaten to attack again, rather than actually launch the attack."

The Right Support: Proactive rather than Reactive

Companies need to review their approaches to protecting their networks. A secure system will implement every software patch and utilize every notification it receives. But a company must think like a hacker -- and start using proactive tools to anticipate the source of an attack, and how it might enter a firm's network. A proactive CIO will:

  • Share secrets with competitors so that everyone in a similar industry is following best practices. If one firm is compromised by a computer attack, a competitor will often find its customers demanding potentially costly assurances of their security. By sharing information with competitors on how each keeps its own system secure before an attack happens, firms can save time and money.

  • Hire firms that specialize in breaking into their IT infrastructure to find vulnerabilities before hackers do. This should be done at least annually, to locate and then neutralize any insecure portal.

  • Demand a direct pipeline to software vendors. Instead of relying on notification messages, major clients of software vendors are eligible for early versions of patches. Hackers understand that an open-patch release dispatched by a software company is an alert to where the vulnerabilities lie in an existing system. Less public communication between CIOs and software vendors will help eliminate this exposure.

  • Train employees to be cautious when callers request information such as their password or user name. "If you did not initiate the conversation, then do not give out your information," says The Honeynet Project's Spitzner. A telephone on an employee's desk is as much of a danger to an IT Infrastructure as a hacker discovering a software flaw. If a hacker can get an employee's name and password, they can have open access to a computer mainframe.

With new ways of thinking, CIOs can start implementing proactive tools to not just react to threats, but anticipate their arrival. A holistic approach -- one that involves not just an IT department and employees, but industry colleagues as well -- is the strongest firewall.

Lauren Barack's work has been published in Business 2.0 and Wired.

Featured Local Company

Centro de Internet J Y R

809-725-5530
calle D no. 14 Ens. 27 de Febrero.
San Francisco de Macoris, MA
centrodeinternetjyr@hotmail.com

Regional Articles
- Anticipating Threats Acton MA
- Anticipating Threats Agawam MA
- Anticipating Threats Allston MA
- Anticipating Threats Amesbury MA
- Anticipating Threats Amherst MA
- Anticipating Threats Andover MA
- Anticipating Threats Arlington MA
- Anticipating Threats Attleboro MA
- Anticipating Threats Beverly MA
- Anticipating Threats Billerica MA
- Anticipating Threats Boston MA
- Anticipating Threats Braintree MA
- Anticipating Threats Bridgewater MA
- Anticipating Threats Brighton MA
- Anticipating Threats Brockton MA
- Anticipating Threats Brookline MA
- Anticipating Threats Buzzards Bay MA
- Anticipating Threats Cambridge MA
- Anticipating Threats Charlestown MA
- Anticipating Threats Chelmsford MA
- Anticipating Threats Chelsea MA
- Anticipating Threats Chicopee MA
- Anticipating Threats Danvers MA
- Anticipating Threats Dedham MA
- Anticipating Threats Dracut MA
- Anticipating Threats East Falmouth MA
- Anticipating Threats East Weymouth MA
- Anticipating Threats Easthampton MA
- Anticipating Threats Everett MA
- Anticipating Threats Fairhaven MA
- Anticipating Threats Fall River MA
- Anticipating Threats Fitchburg MA
- Anticipating Threats Foxboro MA
- Anticipating Threats Framingham MA
- Anticipating Threats Franklin MA
- Anticipating Threats Gardner MA
- Anticipating Threats Gloucester MA
- Anticipating Threats Haverhill MA
- Anticipating Threats Hingham MA
- Anticipating Threats Holyoke MA
- Anticipating Threats Hyannis MA
- Anticipating Threats Hyde Park MA
- Anticipating Threats Jamaica Plain MA
- Anticipating Threats Lawrence MA
- Anticipating Threats Leominster MA
- Anticipating Threats Lexington MA
- Anticipating Threats Longmeadow MA
- Anticipating Threats Lowell MA
- Anticipating Threats Ludlow MA
- Anticipating Threats Lynn MA
- Anticipating Threats Malden MA
- Anticipating Threats Marblehead MA
- Anticipating Threats Marlborough MA
- Anticipating Threats Mattapan MA
- Anticipating Threats Medford MA
- Anticipating Threats Melrose MA
- Anticipating Threats Methuen MA
- Anticipating Threats Middleboro MA
- Anticipating Threats Milford MA
- Anticipating Threats Milton MA
- Anticipating Threats Natick MA
- Anticipating Threats Needham MA
- Anticipating Threats New Bedford MA
- Anticipating Threats Newburyport MA
- Anticipating Threats Newton Center MA
- Anticipating Threats North Adams MA
- Anticipating Threats North Andover MA
- Anticipating Threats North Attleboro MA
- Anticipating Threats North Dartmouth MA
- Anticipating Threats Northampton MA
- Anticipating Threats Norton MA
- Anticipating Threats Norwood MA
- Anticipating Threats Peabody MA
- Anticipating Threats Pittsfield MA
- Anticipating Threats Plymouth MA
- Anticipating Threats Quincy MA
- Anticipating Threats Randolph MA
- Anticipating Threats Revere MA
- Anticipating Threats Roslindale MA
- Anticipating Threats Salem MA
- Anticipating Threats Saugus MA
- Anticipating Threats Scituate MA
- Anticipating Threats Shrewsbury MA
- Anticipating Threats Somerville MA
- Anticipating Threats South Hadley MA
- Anticipating Threats South Weymouth MA
- Anticipating Threats Southbridge MA
- Anticipating Threats Springfield MA
- Anticipating Threats Stoneham MA
- Anticipating Threats Stoughton MA
- Anticipating Threats Swampscott MA
- Anticipating Threats Taunton MA
- Anticipating Threats Tewksbury MA
- Anticipating Threats Walpole MA
- Anticipating Threats Waltham MA
- Anticipating Threats Watertown MA
- Anticipating Threats West Roxbury MA
- Anticipating Threats West Springfield MA
- Anticipating Threats Westborough MA
- Anticipating Threats Westfield MA
- Anticipating Threats Westford MA
- Anticipating Threats Weymouth MA
- Anticipating Threats Winthrop MA
- Anticipating Threats Woburn MA
- Anticipating Threats Worcester MA
Related Local Events
MOBILE INTERNET WORLD 2008
Dates: 10/21/2008 - 10/23/2008
Location: Boston Convention & Exhibition Center
Boston MA
View Details

Embedded Systems Conference Boston
Dates: 10/27/2008 - 10/30/2008
Location: Hynes Convention Center
Boston MA
View Details

Fall VON Conference & Expo
Dates: 10/27/2008 - 10/30/2008
Location: Location To Be Determined
Boston MA
View Details

SD Best Practices Conference & Expo
Dates: 10/27/2008 - 10/30/2008
Location: Hynes Convention Center
Boston MA
View Details

Channel Partners Fall Conference and Expo
Dates: 8/18/2008 - 8/20/2008
Location: World Trade Center Boston and The Seaport Hotel
Boston MA
View Details
Rate Article
     
Articles Insider

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Software
Business Services Fashion Internet Technology
Career Financial Services Legal Telecommunications
Cars Franchise Miscellaneous Trade Shows
Computer Hardware Health Nightlife Travel
Construction Holidays Online Database Weddings
Education Home Appliances Real Estate Resources World History
Entertainment Home Electronics