Old people can sabotage software too
Games insiders play
RSA Software teams must act to protect systems and development projects from revenge attacks by disgruntled current and former employees.
So says Carnegie Mellon Software Engineering Institute's CERT, which is advising organizations take basic steps including code encryption, enforcement of code-change and access controls, reading their log monitors and denying access to non-project staff, such as systems administrators.
"Organizations need to recognize the software they develop is crucial - they need to restrict access and protect systems from administrators who don't need access to that information," Software Engineering Institute business manager Joseph McLeod told the RSA security conference in San Francisco today. "Things like encryption can be used to protect that IP."
Sharing its insights from 245 cases since 1996 on internal attack, CERT told RSA a third of IT attacks come from inside organizations - and that they can inflict as much damage as external hackers in terms of stolen IP, financial loss, and even threats to personal safety.
CERT calls this "IT sabotage" - attacks by disgruntled employees intended to harm an organization directly, by preventing its ability to trade or by causing embarrassment through activities like forwarding private information to customers, competitors or employees, or by binging down a web site.
These differ to attacks from managers stealing trade secrets to enrich themselves and from employees accessing things like customer records to, for example, sell information like social security numbers to identity thieves.
What constitutes a disgruntled employee? Somebody whose expectations have not been meet, such as being passed over for a promotion, or getting let go.
Saboteurs span the ages, from 17 to 70, unlike those simply stealing trade secrets or social security numbers who average out in their mid-30s. "Who'd picture a 60 year old trying to do IT sabotage," Dawn Cappelli, a senior member of SEI technical staff, mused to Reg Dev, after her joint presentation to RSA.
And while the signs of a disgruntled staffer - such as slipping personal hygiene, increased absenteeism, or violent and aggressive behavior - are easy to identify and can be acted on, the tell-tale technical signs often get overlooked by organizations.
These include the insertion of back-door accounts into systems, and the creation of malicious code followed by its testing, installation, downloading and execution.
The most convenient channels to launch what CERT calls "technically sophisticated" attacks are the exploitation of access paths such as those back doors, use of shared or stolen passwords, planting logic bombs, and exploitation of colleagues' machines that have been left running.
Not all attacks are purely digital. Carnegie Mellon recounted the tale of one staffer who stole a contractor's IT badge and used it to access a restricted building, and take down a 9/11 emergency phone number/address look-up system in an attempt to impress a new boss starting work the next day.
For more on the insider threat to software development, see CERT's podcast here.®