<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>

<channel>
	<title>Tek Tips Whitepaper Library &#187; Chris Stoneff</title>
	<atom:link href="http://tek-tips.nethawk.net/blog/author/cstoneff/feed" rel="self" type="application/rss+xml" />
	<link>http://tek-tips.nethawk.net/blog</link>
	<description>Tek Tips Whitepaper Library</description>
	<pubDate>Thu, 29 Jul 2010 18:27:41 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Mismanaged Privileged Accounts: A New Threat To Your Sensitive Data</title>
		<link>http://tek-tips.nethawk.net/blog/mismanaged-privileged-accounts-a-new-threat-to-your-sensitive-data</link>
		<comments>http://tek-tips.nethawk.net/blog/mismanaged-privileged-accounts-a-new-threat-to-your-sensitive-data#comments</comments>
		<pubDate>Fri, 11 Dec 2009 14:53:26 +0000</pubDate>
		<dc:creator>Chris Stoneff</dc:creator>
		
		<category><![CDATA[Community Manager]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Cyber Warfare]]></category>

		<category><![CDATA[Data Security]]></category>

		<guid isPermaLink="false">http://tek-tips.nethawk.net/blog/?p=2400</guid>
		<description><![CDATA[In mid-October the USCC congressional commission gave IT professionals an early Halloween scare with its report on an emerging cyber warfare threat. The 88 page document, compiled by a team at Northrop Grumman, presents in unsettling detail the anatomy of a 2008 attack on a US company&#8217;s IT infrastructure that succeeded in providing at least [...]


Related posts:<ol><li><a class='blue_bold_text' href='http://tek-tips.nethawk.net/blog/the-informationization-age' rel='bookmark' title='Permanent Link: The Informationization Age'>The Informationization Age</a></li><li><a class='blue_bold_text' href='http://tek-tips.nethawk.net/blog/shavlik-statement-on-patch-tuesday-by-jason-miller-data-and-security-team-leader-shavlik-technologies-st-paul-mn' rel='bookmark' title='Permanent Link: Shavlik statement on Patch Tuesday by Jason Miller, Data and Security Team Leader, Shavlik Technologies, St. Paul, MN'>Shavlik statement on Patch Tuesday by Jason Miller, Data and Security Team Leader, Shavlik Technologies, St. Paul, MN</a></li><li><a class='blue_bold_text' href='http://tek-tips.nethawk.net/blog/shavlik-comments-on-february-patch-tuesday-releases' rel='bookmark' title='Permanent Link: Shavlik Comments on February Patch Tuesday Releases'>Shavlik Comments on February Patch Tuesday Releases</a></li></ol>]]></description>
			<content:encoded><![CDATA[<p>In mid-October the USCC congressional commission gave IT professionals an early Halloween scare with its report on an emerging cyber warfare threat. The 88 page document, compiled by a team at Northrop Grumman, presents in unsettling detail the anatomy of a 2008 attack on a US company&#8217;s IT infrastructure that succeeded in providing at least some measure of sensitive data to overseas spies. The report makes this gloomy assessment:</p>
<blockquote><p><em>&#8220;US government and private sector information, once unreachable or requiring years of expensive technological or human asset preparation to obtain, can now be accessed, inventoried, and stolen with comparative ease using computer network operations tools.&#8221;</em></p></blockquote>
<p>The USCC report details how overseas agents use a multi –faceted approach to create potent cyber attacks. First, they combine zero-day exploits they develop in-house with clever social engineering to deliver malicious payloads onto target systems with surprising consistency.</p>
<table>
<tr>
<th width="35" rowspan="3">&nbsp;</th>
<td colspan="2">- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -</td>
</tr>
<tr>
<td><img src="http://tek-tips.nethawk.net/logos/1251999351_coverity100x21.gif"></td>
<td style="font-family: Helvetica, Verdana, sans-serif;"><a href="http://tek-tips.nethawk.net/registration_dynamic.php?id=312">Improving Software Quality to Drive Business Agility</a></td>
</tr>
<tr>
<td colspan="2"> - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -</td>
</tr>
</table>
<p>Once a single computer is compromised, the intruders leapfrog from system to system, compromising &#8220;highly sensitive privileged accounts&#8221; throughout the organization until the infrastructure is mapped and its most valued information can be extracted quickly enough to render conventional safeguards powerless. The report sums it up by saying,</p>
<blockquote><p><em>&#8220;These operators exploit this reactive defense model and they have the resources necessary to develop and exploit previously unknown vulnerabilities that are often missed by signature-based IDS/IPS and endpoint protection software.&#8221;</em></p></blockquote>
<p>With no end in sight to new vulnerabilities that appear in desktop applications, web services, operating systems and even network appliances, how can organizations safeguard their most sensitive data from attack?</p>
<p>Today there&#8217;s a software solution that, within a short period of time, can discover and catalog the privileged accounts everywhere in your enterprise – in applications and web services, databases, operating systems, and so on. The software then isolates interdependent services to maintain the absolute minimum of commonality among privileged credentials, continuously hardening and changing all of the passwords and permitting delegated check-out only by authorized IT staff. That way a single compromised system has only short-term value and can&#8217;t become an easy launching point to expose your entire infrastructure.</p>
<p>To download a copy of the USCC report visit <a href="http://www.uscc.gov/researchpapers/2009/NorthropGrumman_PRC_Cyber_Paper_FINAL_Approved%20Report_16Oct2009.pdf">http://www.uscc.gov/researchpapers/2009/NorthropGrumman_PRC_Cyber_Paper_FINAL_Approved%20Report_16Oct2009.pdf</a>.</p>
<p>Chris Stoneff, principal product manager at <a href="http://www.liebsoft.com" target="_blank">Lieberman Software Corporation</a>, a Los Angeles-based developer of privileged identity management software.</p>


<p>Related posts:<ol><li><a class='blue_bold_text' href='http://tek-tips.nethawk.net/blog/the-informationization-age' rel='bookmark' title='Permanent Link: The Informationization Age'>The Informationization Age</a></li><li><a class='blue_bold_text' href='http://tek-tips.nethawk.net/blog/shavlik-statement-on-patch-tuesday-by-jason-miller-data-and-security-team-leader-shavlik-technologies-st-paul-mn' rel='bookmark' title='Permanent Link: Shavlik statement on Patch Tuesday by Jason Miller, Data and Security Team Leader, Shavlik Technologies, St. Paul, MN'>Shavlik statement on Patch Tuesday by Jason Miller, Data and Security Team Leader, Shavlik Technologies, St. Paul, MN</a></li><li><a class='blue_bold_text' href='http://tek-tips.nethawk.net/blog/shavlik-comments-on-february-patch-tuesday-releases' rel='bookmark' title='Permanent Link: Shavlik Comments on February Patch Tuesday Releases'>Shavlik Comments on February Patch Tuesday Releases</a></li></ol></p>]]></content:encoded>
			<wfw:commentRss>http://tek-tips.nethawk.net/blog/mismanaged-privileged-accounts-a-new-threat-to-your-sensitive-data/feed</wfw:commentRss>
		</item>
	</channel>
</rss>
