GRC Journal - (Page 43) DON’T WAIT FOR THE HURRICANE TO HIT NEIL MACDONALD, VP and Distinguished Analyst, Gartner, Inc., says the big priorities for 2007 will be getting a handle on unmanaged devices and unmanaged machines connecting to enterprises’ networks. He also believes most organizations will be affected by some amount of targeted, financially motivated software that is undetectable using traditional security protection technologies. What types of threats evoke the need for specialized security measures as more and more niche players become apparent in a highly competitive marketplace? Companies need to beware of targeted attacks; attacks that are confined to a small number, or even a single organization. The problem with targeted attacks is that they completely break the legacy signature-based model of the anti-virus vendors. The signature anti-virus model depends on a large enough number of people seeing something to raise visibility so that anti-virus vendors’ labs can develop a signature, and then the rest of us benefit from somebody else being hit. However, with targeted attacks where the malicious code is sent to only a small number of companies for the purpose of financial gain, the attack will likely not create the visibility necessary for the anti-virus vendors to create a signature. Targeted attacks are completely undetected by traditional signature-based mechanisms. The changing motivation of hackers – from mass publicity to financial motives – is part of the reason behind the shift to targeted attacks. Hackers are no longer in the game for the fame and glory of taking down a million PCs; they are in it for financial gain – stealing intellectual property, stealing customer and consumer data, and holding enterprise data for ransom. 172 BTQ Business Trends Quarterly Q1 2007 | www.btquarterly.com http://www.btquarterly.com
For optimal viewing of this digital publication, please enable JavaScript and then refresh the page. If you would like to try to load the digital publication without using Flash Player detection, please click here.