Big Data. Big Decisions
InformationWeek
Special Coverage Series


10 Best Ways To Stop Insider Attacks

Consider the smartest ways that companies can detect, block, and investigate insiders with malicious motives. The advice comes from CERT and the Secret Service, after a review of hundreds of attacks.

10 Massive Security Breaches
(click image for larger view)
Slideshow: 10 Massive Security Breaches

What's the best way to spot and block insider attacks? Start by putting an insider attack prevention program in place.

More Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

So said Dawn Cappelli, technical manager at Carnegie Mellon University's CERT Insider Threat Center, speaking last month at the RSA conference in San Francisco. Cappelli is the co-author, with Andrew Moore and Randall Trzeciak, of the just-released The Cert Guide To Insider Threats.

Working with the Secret Service, Cappelli and company have reviewed hundreds of hacking cases to deduce how businesses can better block a greater number of malicious insiders. Here are her top 10 recommendations for spotting and stopping insider attacks before they get out of hand:

[ Do you employ a hacker? See How To Spot Malicious Insiders Before Data Theft. ]

1. Protect crown jewels first. To put an effective insider-threat program in place, first ask: What's the single most important piece of information in your company? Think the equivalent of the secret recipe for Coke or Gore-Tex. "We've worked with a number of organizations, and they tell us everything is important," said Cappelli. "So we say, what's the one thing that if someone took it to a competitor, or out of the United States, would be worth millions--or billions--of dollars?" Then secure it, preferably not just with encryption, but also by restricting access, as well as logging and monitoring who touches that data.

2. Learn from past attacks. Don't let insider attacks--successful or otherwise--go to waste. "If you experience an attack, you're not alone, but learn from it," said Cappelli. For example, she cited a case of a financial firm that happened to catch an employee who was trying to steal its secret trading algorithms. Seeing a weak point, the security team put new controls in place to explicitly watch for similar types of attacks. Thanks to the improved security, they later caught another employee who was trying to copy the algorithms to his personal email account and an external hard drive.

3. Mitigate trusted business partner threats. Who has access to your business' sensitive information? Although that list will include employees, other "insiders" will be trusted business partners, who might enjoy equal levels of access with less accountability, and opt to take sensitive information with them when they switch to a new employer. "The good news is, if they take it to a competitor in the U.S., there's a good chance that they may report them to law enforcement and they'll get it back," Cappelli said, since most will want nothing to do with trade secrets. The bad news is that one-third of all intellectual property theft cases result in the information being taken outside of the United States, at which point recovering the data becomes unlikely, if not impossible.

4. Make suspect behavior cause for concern. Watch for human-behavior warning signs. Indeed, in reviewing numerous cases of insider theft, Cappelli said that concerning behaviors were the fourth most likely sign that there was an inside-theft issue. "We usually call these people as being 'on the HR radar,'" she said. Accordingly, watch for warning signs, and have a response plan in place for when such signs get spotted.

5. Train employees to resist recruiters. "Many employees who commit fraud are recruited from outside," said Cappelli, and insiders often say that they're not committing a crime, but rather just giving data to someone else, who then commits a crime. Alter such thinking by creating clear, related security policies, and broadcasting the fact that all data access is audited. Via Cappelli, here's sample boilerplate: "If you get caught, we log everything that everyone does here, and the evidence is going to point to you."

6. Beware resignations, terminations. Most insider attacks occur within a narrow window. "The good news about [insider] crime, theft of intellectual property, is that most people who steal it do [so] within 30 days of resignation," said Cappelli. (The exception is fraud, which--as long as the attacker is making money--can continue indefinitely.) In other words, malicious insiders are most likely to strike 30 days before or after they leave. Accordingly, keep a close eye on departing or departed employees, and what they viewed. "Know what your crown jewels are," she said. "If someone resigns who had access to your crown jewels, you need to go back and proactively investigate that."

7. Apply current technology How can businesses take their current technology and use it to spot suspected insider theft? "A lot of people spend a lot of money on tools, on technologies, and most of those tools are focused on keeping people outside of your network," said Cappelli. "What we've found is that you can use those same tools, but differently," to watch for information that may be exiting your network. For example, centralized logging tools can be used to spot signs of data exfiltration, for example if a "departing insider" has sent an email in the past 30 days to someone outside the corporate domain, and which exceeds a certain specified file size.

8. Beware employee privacy issues. When creating an insider-theft-prevention program, always work with your company's general counsel, because privacy laws vary by state and country. "There are a number of issues regarding employee privacy, I know they can be overcome, but it has to be done very carefully," said Cappelli.

9. Marshall forces. As with many aspects of security--including data breaches--businesses that prepare for attacks in advance tend to better manage the aftermath. When it comes to combating cases of suspected insider threat, include "HR, management, upper management, security, legal, software engineering--you need to involve all of those organizations--and of course IT and information security," Cappelli said.

10. Get started. Perhaps the most important insider-threat tip is simply to get a program in place, as soon as possible. "I'm not saying the sky is falling," said Cappelli. But creating such a program takes time. Perhaps the best place to start, she said, is to get buy-in from all senior managers. For example, she recently worked with a business that gathered all 23 of its c-level managers in a room for two days, during which time they created--and agreed on--an insider-threat program from the ground up.

One of the biggest insider-theft-prevention lessons to learn, said Cappelli, is that technology alone often won't block such attacks. A corollary to that, meanwhile, is that by combining proper policies and procedures with awareness and having an insider-theft reaction plan already in place, businesses can more quickly combat suspected attacks. Because whether it's a question of preventing intellectual property from leaving the building or spotting fraudulent activity, "our goal is to stop an insider as soon as possible," she said.

InformationWeek is conducting a survey to determine the types of measures and policies IT is taking to ensure the security of the full range of mobile assets on cellular, Wi-Fi, and other wireless technologies. Upon completion of our survey, you will be eligible to enter a drawing to receive an 32-GB Apple iPod Touch. Take our Mobile Security Survey now. Survey ends March 16.



Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

BYTE encourages readers to engage in spirited, healthy debate, including taking us to task. However, BYTE moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. BYTE further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.

Follow InformationWeek

By The Numbers

What Are Your Primary Concerns About Using Big Data Software?

Base: 417 respondents at organizations using or planning to deploy data analytics, BI or statistical analysis software
Data: InformationWeek 2013 Analytics, Business Intelligence and Information Management Survey of 541 business technology professionals, October 2012

What Do You Think?

What's your attitude about SQL analysis on top of Hadoop?
We want fast, standard SQL analysis capabilities on Hadoop ASAP
Hadoop is for unstructured data; SQL is for relational databases
We'll give SQL on Hadoop a try, but relational DBs will remain the mainstay
Given strong SQL support on Hadoop, we'd nix the data warehouse
We're not interested in Hadoop
No opinion



Related Content

From Our Sponsor

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Business leaders often need a visual snapshot of data to quickly grasp and use it. This paper identifies five challenges in presenting data and how visual analytics can resolve them. Solutions are suggested to overcome the challenges of: speed, data clarity, data quality, displaying meaningful results, and dealing with outliers.

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Today's competitive advantage requires a deeper understanding of your business, your market and your customers. As an IT executive, you can drive that knowledge transformation. In this white paper, learn how to make decisions as a strategic business leader and three steps to begin an analytics initiative within your enterprise.

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

High-performance data visualization turns sophisticated analyses into meaningful graphics, leading to faster and smarter decision making. In this white paper, learn how visual analytics can transform big data, with additional features such as real-time functionality, mobile compatibility, robust applications for technical groups and accessibility for nontechnical users.

Big Data: Lessons from the Leaders

Big Data: Lessons from the Leaders

Financial performance, competitive advantage, operational efficiency, strategic decision making - every business goal can extract value from big data, and the time for doubt or inaction has long passed. In this Economist Intelligence Unit report, in-depth interviews with data pioneers reveal the link between the effective use of big data and the bottom line among other results.

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Which came first, the data or the decision? This white paper makes the case for having a decision in mind, then tailoring big data's volume, variety and velocity to achieve business results such as overcoming customer dissatisfaction or creating well-informed strategies in real time.

Informationweek Reports

Research: The Big Data Management Challenge

Research: The Big Data Management Challenge

The challenge of big data is real, but most organizations don't differentiate 'big data' from traditional data, and nearly 90% of respondents to our survey use conventional databases as the primary means of handling data. We'll help you understand what constitutes big data (it's not just size) and the numerous management challenges it poses.