Looking Out for Insider Threats Maryland

If the topic of protecting against insider threats makes many a government IT worker shudder, it's for good reason. Besides the millions of people employed by government agencies, the number of federal civil servants is on the rise, as is the number of people working for government-funded contractors and organizations that receive government grants. Add to that the number of postal workers and military personnel, and the "true size" of the federal government is around 14.6 million employees, according to Paul C. Light, government professor at New York University.

Local Companies

The Peters Group
(301) 805-2113
6911 Laurel Bowie Rd
Bowie, MD
C Ross Menchey
(410) 321-4866
1817 Landrake Rd
Towson, MD
R B Family
(410) 763-7075
8600 Brooks Dr
Easton, MD
Leadership Concepts Development
(301) 567-5757
9301 Ivanhoe Rd
Fort Washington, MD
Eight P Cpl
(410) 379-2675
6725 Santa Barbara Ct
Elkridge, MD
Kinsley Management 1001 Partnership
(410) 272-0355
1003 Old Philadelphia Rd
Aberdeen, MD
Mariner Management & Marketing
(301) 725-2508
3517 Forest Haven Dr
Laurel, MD
Barton White Associates
(410) 557-0459
White Hall, MD
Keys Management and Training
(410) 448-2227
4111 Springdale Ave
Gwynn Oak, MD
American Lead Consultants
(301) 893-0445
179 Smallwood Village Ct
Waldorf, MD



Stacey McDaniel

If the topic of protecting against insider threats makes many a government IT worker shudder, it's for good reason. Besides the millions of people employed by government agencies, the number of federal civil servants is on the rise, as is the number of people working for government-funded contractors and organizations that receive government grants. Add to that the number of postal workers and military personnel, and the "true size" of the federal government is around 14.6 million employees, according to Paul C. Light, government professor at New York University.

That's a lot of insiders.

IT threats from employees or contractors are a real problem -- and one of the most difficult problems managers must face because of the trusted position that insiders have. Various research estimates that up to 80% of security threats come from someone inside the organization. All it takes is one person to cause irreparable damage to an agency's data, systems, operations and reputation. The federal government's dependence on interconnected networks and communications systems significantly increases the risk of harm that could result from malicious inside activity. Therefore, it's critical that government agencies educate their employees to watch out for tell-tale characteristics of an attacker, and to employ security solutions designed to detect and deter these threats.

Identifying behaviors
Being able to recognize certain behaviors or traits commonly exhibited by employees preparing for an IT attack can help thwart a potential problem. The findings of a survey conducted by the U.S. Secret Service in 2006 show that internal compromises of computers and networks aren't an impulsive undertaking -- most are planned in advance. This means that educated employees and alert managers can often spot signs of potential attackers before a problem escalates.

Here are some of the other findings from the Secret Service study:

  • 80% of insiders who launched attacks on their companies had exhibited negative behaviors before the incident.
  • 92% had experienced a negative work-related event, such as a demotion, transfer, warning, or termination.
  • At the time of the incident, 59% were former employees or contractors, while 41% were still on the company payroll.
  • Of the former employees, 48% had been fired, 38% had resigned, and 7% had been laid off.
  • 86% were employed in a technical position. Of those, 38% were system administrators.
  • 21% were programmers, 14% were engineers, and 14% were IT specialists.
  • 96% of the inside attackers were male.
  • Just under one-third of the insiders had an arrest history.
  • 57% of insiders were perceived by others to be disgruntled.
  • The majority of insiders compromised computer accounts, created unauthorized backdoor accounts, or used shared accounts in their attacks.
  • Remote access was used to carry out the majority of the attacks.
  • The most frequently reported motive was revenge.

In June 2007, the Office of the National Counterintelligence Executive their own set own set of guidelines, intended to help government employees know how to identify, and then report, behavior that is indicative of a potential insider threat.

Security precautions
While securing the IT perimeter from external threats is essential, knowing and controlling who does what inside the perimeter is equally important. This requires network access control as well as endpoint and database security solutions.

Network Access Control makes sure that each endpoint connected to the networks is compliant with the agency's security and access policies. This stops unauthorized endpoints from gaining access and also prevents compromises from remote employees.

Endpoint Protection proactively analyzes application behaviors and network communications to detect and block attacks. Should a disgruntled insider try to run exploits like rootkits or spyware on an internal endpoint, this activity will be detected before it happens. Protection features also block read/write/execute commands from removable drives and prevent unauthorized applications from running on protected systems.

Database Security detects malicious database activity from legitimate users and provides an audit trail for all database activity. The solution's intelligent profiling technology automatically learns "normal" database usage patterns and alerts administrators when suspicious activity occurs.

The government is brimming with employees and contractors who have been given some form of access to the networks and communications systems on which our government operates. At the same time, insider threats are becoming more common, and they can be especially difficult to detect and thwart. Government IT systems hold information crucial to our national security, and can't afford the risk of an internal compromise. However, knowing the warning signs to look for and combining that knowledge with internal IT security measures are the best ways to keep the government's networks secure and national security intact.

Stacey McDaniel has been writing about high-tech issues for more than six years.

Regional Articles
- Looking Out for Insider Threats Annapolis MD
- Looking Out for Insider Threats Baltimore MD
- Looking Out for Insider Threats Bel Air MD
- Looking Out for Insider Threats Beltsville MD
- Looking Out for Insider Threats Bethesda MD
- Looking Out for Insider Threats Bowie MD
- Looking Out for Insider Threats Brooklyn MD
- Looking Out for Insider Threats Capitol Heights MD
- Looking Out for Insider Threats Catonsville MD
- Looking Out for Insider Threats Chevy Chase MD
- Looking Out for Insider Threats Clinton MD
- Looking Out for Insider Threats Cockeysville MD
- Looking Out for Insider Threats College Park MD
- Looking Out for Insider Threats Columbia MD
- Looking Out for Insider Threats Crofton MD
- Looking Out for Insider Threats Cumberland MD
- Looking Out for Insider Threats Derwood MD
- Looking Out for Insider Threats District Heights MD
- Looking Out for Insider Threats Dundalk MD
- Looking Out for Insider Threats Edgewood MD
- Looking Out for Insider Threats Elkridge MD
- Looking Out for Insider Threats Elkton MD
- Looking Out for Insider Threats Ellicott City MD
- Looking Out for Insider Threats Essex MD
- Looking Out for Insider Threats Forest Hill MD
- Looking Out for Insider Threats Fort Washington MD
- Looking Out for Insider Threats Frederick MD
- Looking Out for Insider Threats Frostburg MD
- Looking Out for Insider Threats Gaithersburg MD
- Looking Out for Insider Threats Germantown MD
- Looking Out for Insider Threats Glen Burnie MD
- Looking Out for Insider Threats Greenbelt MD
- Looking Out for Insider Threats Gwynn Oak MD
- Looking Out for Insider Threats Hagerstown MD
- Looking Out for Insider Threats Halethorpe MD
- Looking Out for Insider Threats Havre De Grace MD
- Looking Out for Insider Threats Hyattsville MD
- Looking Out for Insider Threats Jessup MD
- Looking Out for Insider Threats Joppa MD
- Looking Out for Insider Threats Kensington MD
- Looking Out for Insider Threats La Plata MD
- Looking Out for Insider Threats Lanham MD
- Looking Out for Insider Threats Laurel MD
- Looking Out for Insider Threats Lexington Park MD
- Looking Out for Insider Threats Lusby MD
- Looking Out for Insider Threats Lutherville Timonium MD
- Looking Out for Insider Threats Middle River MD
- Looking Out for Insider Threats Millersville MD
- Looking Out for Insider Threats Montgomery Village MD
- Looking Out for Insider Threats Mount Airy MD
- Looking Out for Insider Threats Nottingham MD
- Looking Out for Insider Threats Odenton MD
- Looking Out for Insider Threats Olney MD
- Looking Out for Insider Threats Owings Mills MD
- Looking Out for Insider Threats Oxon Hill MD
- Looking Out for Insider Threats Parkville MD
- Looking Out for Insider Threats Pasadena MD
- Looking Out for Insider Threats Pikesville MD
- Looking Out for Insider Threats Potomac MD
- Looking Out for Insider Threats Randallstown MD
- Looking Out for Insider Threats Reisterstown MD
- Looking Out for Insider Threats Rockville MD
- Looking Out for Insider Threats Rosedale MD
- Looking Out for Insider Threats Salisbury MD
- Looking Out for Insider Threats Severn MD
- Looking Out for Insider Threats Severna Park MD
- Looking Out for Insider Threats Silver Spring MD
- Looking Out for Insider Threats Suitland MD
- Looking Out for Insider Threats Sykesville MD
- Looking Out for Insider Threats Takoma Park MD
- Looking Out for Insider Threats Temple Hills MD
- Looking Out for Insider Threats Towson MD
- Looking Out for Insider Threats Upper Marlboro MD
- Looking Out for Insider Threats Waldorf MD
- Looking Out for Insider Threats Westminster MD
- Looking Out for Insider Threats Windsor Mill MD
Related Local Events
ICC - International Code Council Annual Conference
Dates: 11/1/2009 - 11/4/2009
Location: Baltimore Convention Center
Baltimore, MD
View Details

MID-ATLANTIC ALL HAZARDS FORUM & EXHIBITION 2009
Dates: 11/1/2009 - 11/1/2009
Location: Baltimore Convention Center
Baltimore, MD
View Details

Gartner IT Security Summit Washington
Dates: 6/27/2009 - 6/28/2009
Location: Gaylord National Hotel & Convention Center
National Harbor, MD
View Details

First Look: Windows Vista for IT Professionals
Dates: 6/11/2009 - 6/11/2009
Location: Source - Hunt Valley
Hunt Valley, MD
View Details

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Real Estate Resources
Business Services Fashion Industrial Goods & Services Retail & Consumer Services
Career Financial Services Insurance Software
Cars Food & Beverage Internet Technology
Computer Hardware Franchise Legal Telecommunications
Construction Health Miscellaneous Trade Shows
Education Holidays Nightlife Travel
Entertainment Home Appliances Online Database Weddings
Environmental Home Electronics Pets World History