The chapter highlights a wide range of technologies and methods that can be used by an insider to cause harm to a company. Just like viruses and other attacks, attackers are often taking a base method and modifying or creating variants of it to make it more powerful and difficult to attack. The same thing occurs with the insider threat. The chapter explains the base technologies and some variants but expect to see additional variants and new methods evolve. As companies become more and more savvy on prevention and detection techniques for insider threat, attackers are going to be forced to enhance their means and methods of using these technologies and even, in some cases, developing new technologies. Threat is tied back to possible danger and created by attackers. Every time an attacker develops a new method or technique for exploiting a system, the attacker creates a new threat and in most cases, there is a high chance that the company has a resulting vulnerability. The reason is simple—attackers develop methods to break in and cause harm, which is manifested through vulnerability. If there is no vulnerability, the attacker spends all this effort on a technique that will never amount to anything of value.
The chapter discusses unique insider threats to state and local government institutions. This includes organizations, such as mass transit, utilities, and licensing agencies. State and local governments are frequent victims of insiders. The chapter provides a number of case studies to explain their subsequent effect at the local and state level. Corruption within state and local government does happen and on a consistent basis. On an average, 249 states and local officials are charged with corruption each year, 206 are prosecuted, and 92 await trial. Potential threats are categorized as a loss of safety and/or loss of property. Sometimes the threat of sabotage can be almost as damaging as the act itself. At the home or office, possible threats include first responders, water, electricity, natural gas, telephone, and Internet service. Away from the home or office, threats include traffic control systems, mass transit, voting safety, and licensing organizations. The difference between prevention and deterrence is that the first removes the vulnerability, whereas the latter attempts to convince the individual from not exploiting it. Whenever possible, always prevent and use deterrence as a last resort or as an additional layer of security.
The Secret Service, FBI, NSA, CERT (Computer Emergency Response Team) and George Washington University have all identified Insider Threats as one of the most significant challenges facing IT, security, law enforcement, and intelligence professionals today. This book will teach IT professional and law enforcement officials about the dangers posed by insiders to their IT infrastructure and how to mitigate these risks by designing and implementing secure IT systems as well as security and human resource policies. The book will begin by identifying the types of insiders who are most likely to pose a threat. Next, the reader will learn about the variety of tools and attacks used by insiders to commit their crimes including: encryption, steganography, and social engineering. The book will then specifically address the dangers faced by corporations and government agencies. Finally, the reader will learn how to design effective security systems to prevent insider attacks and how to investigate insider security breeches that do occur. Throughout the book, the authors will use their backgrounds in the CIA to analyze several, high-profile cases involving insider threats. * Tackles one of the most significant challenges facing IT, security, law enforcement, and intelligence professionals today* Both co-authors worked for several years at the CIA, and they use this experience to analyze several high-profile cases involving insider threat attacks * Despite the frequency and harm caused by insider attacks, there are no competing books on this topic.books on this topic