security policy related to a bomb threat

profileyellancnigg
Introduction_to_Security_----Chapter17.pdf

Introduction to Security Ninth Edition. DOI: © 2013 Elsevier Inc. All rights reserved.

435 2013

10.1016/B978-0-12-385057-7.00017-8

Computer Technology and Information Security Issues

OBJECTIVES

The study of the chapter will enable you to:

1. Identify various computer products.

2. Discuss possible attacks on computer systems and software.

3. Discuss options for protecting computers and information from fraudulent use and theft.

Introduction Computers and information systems have traditionally been treated as something that the security/loss-prevention director needs to consider as a vulnerability; however, the 21st century has brought about a revolution in security operations. The following discussion on computers and information systems security will focus primarily on the services provided by the traditional roles of security in protecting computers. However, the trend is for security technologies to rely on the very computers that they are designed to protect. For example, information technology has bought closed-circuit television (CCTV), primarily used for surveillance, of age. Technologies like biometrics1 have made possible video monitoring in the areas of facial and physical characteristics recognition, fire and smoke detection, and advanced alarm monitoring. With this growing integration of technology and the security operation, the traditional dichotomy associated with security and information technology often creates problems.

In 1946 the U.S. Army developed ENIAC (Electronic Numerical Integrator and Calculator), the first viable full-scale computer. At that time, computers were mysterious boxes utilized by scientists and thought to be the top-secret weapons of generals. Today, scientific pocket calculators have greater computing power than ENIAC, and most kindergarten kids know how to use a computer2 or some type of handheld personal digital assistant (PDA) computing device, particularly those designed for electronic games. Computers have become an important part of peoples’ lives, becoming an integral part of the way we work, teach, learn, and even play.

In government and business, computers are used to process, store and transmit vast amounts of information. Information processing tasks that used to take days or weeks for workers to compile are handled by today’s computers in mere minutes, translating into greater efficiencies and greater productivity. Moreover, information systems are becoming primary methods of communications. E-mail, instant messaging, voice-over Internet protocol

17

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

436 INTRODUCTION TO SECURITY

(essentially using computers and the Internet for voice communications, until recently the exclusive capability of telephones and telephone companies) are common and in many cases essential means of effective and efficient communications. Cellphones, smart phones (e.g.,  iPhone, Blackberry, Android) and laptops, along with tablet computers and electronic book readers, are virtually ubiquitous in today’s society.

The criminal justice sector also relies on computers. Since 1924 the Federal Bureau of Investigation (FBI) has been responsible for keeping the nation’s fingerprint and criminal history records. In 1967 the National Crime Information Center (NCIC) was established. Today the FBI has a computer system they call the Investigative Data Warehouse (IDW), described as one-stop shopping, giving FBI agents, from anywhere in the world, almost instant access to a database containing more than 650 million records. The search capability of this system has been described as an “Uber-Google.”3

In the private sector, banks, insurance agencies, and credit rating agencies also process enormous volumes of computer data. For example, in the early part of this decade it was estimated that TRW Data Systems of California collected, stored, and sold access to information containing the credit histories of more than 90 million Americans. Banks, depart- ment stores, jewelry stores, and credit card companies pay them a subscription fee to access such information on current and potential customers. Today, Choicepoint, acquired by Reed Elsevier in September 2008, is a leading information broker with personal files on more than 220 million people in the United States and Latin America. This data is for sale to government organizations and the private sector.4 Likewise, every major insurance company in America collects and stores information on past, current, and future policyholders.

Telemarketing and mail order professionals similarly buy, sell, and repackage such information like so many tangible products. The countless pieces of junk mail stuffed in Americans’ mailboxes each day attest to the proliferation of such information brokers. Information brokers sell personal data to companies who then target for mail campaigns people who might be interested in their products.

The Dow Jones News/Retrieval Service offers stock market quotations, reports on business and economic forecasts, plus profiles of companies and organizations. The Source not only pro- vides news and stock market indexes but also provides games and other forms of entertainment to its subscribers. Each of these information services is available to anyone with a computer, lap- top, iPad, smart phone or any other type of personal digital assistant (PDA) device.

However, as with all great advances, there is a downside. Computer technology is changing so fast that equipment and software are often outdated before or as soon as it is installed, having a negative impact on the profit margin of the company. This is especially true for microcomputers.5

Of greater importance for the security professional are the criminal activities associated with the misuse of computers and the technology supported by them. Early in the 21st century, one of the fastest growing problems in this arena is identify theft. Problems that did not exist 25 years ago are commonplace today. For example, 25 years ago, few people had any fear of computer viruses. Today several major firms are in the business of protecting not only company computers, but also the computers used at home, from destructive viruses.

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

Chapter 17 l Computer Technology and Information Security Issues 437

CSO, CISO and CIO Interactions Information and information systems have become so critical to the efficient operation of business and government that organizations have in place senior executives to direct strate- gic and tactical operations associated with the creation, processing, transmission, storage and protection of information. Virtually all major corporations and government organizations have in place chief information officers (CIO) and chief information security officers (CISO). These executives either hold a seat in the C-suite (a term used to refer to corporate and organiza- tional positions of the chief executive level for a particular function, most commonly the chief executive officer (CEO), chief financial officer (CFO), chief technology officer (CTO) and in the security profession, the chief security officer (CSO)) or directly report to someone with “chief ” responsibilities.

The CIO and CISO work closely with the CSO and in most organizations have distinctively separate responsibilities. Where the CIO is responsible for the delivery of information services capabilities to the company, its workforce and other stakeholders, the CISO is responsible for the security of those information systems and the information contained within. In more  traditional companies, the CSO is responsible for determining the sensitivity of information and is responsible for the protection of information when it is not residing within information systems. More specifically, CSOs have been, and often still are, responsi- ble for the protection of information when it is in forms other than electronic. For example, much information exists in the form of documents. These documents, when containing pages of sensitive information, require protection. This protection usually is accomplished with more traditional security methods such as locked containers, files and safes kept in secure or protected company areas where unauthorized persons are not allowed physical access. These traditional security methods help prevent compromise or theft of sensitive company or organi- zation information. In some companies and organizations the CISO duties are assigned to the CSO; however, it is more common to see them separated or to see a CISO reporting to a CSO.

Furthermore, CSOs are often charged with the responsibility of working with the creators of information and intellectual property attorneys to determine and assign some level of sensitivity to information. Information has different degrees of value and sensitivity. Some information is routine business information with no particular sensitivity or value while other information may contain trade secrets or strategic data that possess high value to the organi- zation and perhaps even provide the organization with a unique competitive advantage. To properly protect sensitive information it is essential to be able to identify that information that is truly sensitive and separate it from less valuable information, by virtue of a physical separa- tion or a process of uniquely identifying (marking) that sensitive information so it is clear to the possessor just how sensitive that information is. Moreover, the CSO is generally charged with developing procedures for protecting information determined to be sensitive when not contained within information systems and with ensuring the workforce understands how to protect sensitive information.

Essentially, the CIO, CSIO and CSO are collectively responsible for protecting the confiden- tiality, integrity and availability of all company or organization information. Confidentiality

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

438 INTRODUCTION TO SECURITY

of information is the process of ensuring only authorized persons have access to protected information and that same information is used only for authorized purposes. Integrity of information is the process of ensuring the information is not manipulated in an unauthorized way or corrupted, thus diminishing its value and utility to the organization. Availability of information is the process of information being made available for authorized business use to authorized persons when they need access to perform work on behalf of the company or organization. Properly maintaining information in these three conditions—confidentiality, integrity and availability—is particularly complex and difficult for information residing on electronic information systems.

IT and Security Cooperation

The importance of cooperation between the CIO, CISO and CSO is critical if the organiza- tion is going to successfully protect information and information systems. It is best expressed by the reported responses of CIOs to the 2003 CIO Magazine survey. According to this report, security that had once been on the bottom half of the CIO spending lists has now moved to the fourth highest priority. Only systems and process integration, and finding ways to lower cost, are at the top, ahead of security. And even these priorities are of concern to the CSO.6 However, the global economic recession, which began in 2008 and as of early 2012 has shown some improvement (but with economic forecasts indicating slow growth over the next several years), has adversely impacted corporate IT spending. In late 2010, Gartner predicted informa- tion technology (IT) executives would shift their spending focus to IT infrastructure upgrades.7 What impact that will have on security-related spending remains to be seen.

Types of Computer Systems Regardless of the type of computer system a given agency or company is using, there are four common elements: input, processing, storage, and output. Input refers to entering data and programs into the computer. This can be accomplished by using a keyboard, mouse, scanner, voice recognition software, or telecommunications methods such as traditional phone lines or wireless transmissions. Processing transforms the input into machine instructions. These instructions then exist in executable form within the computer. Hardware components such as the central processing unit (CPU), memory, and basic input/output system (BIOS) affect the computer’s ability to process the input. Storage is a generic term that refers to the areas of a computer and associated media that store information such as data and programs. Examples of storage include internal or main memory, tapes, zip drives, hard disks, CD-ROMs, and memory sticks. Output is any on-screen result or printed report generated by the computer. Output devices are printers, monitors, and communication data.8

Microcomputers, minicomputers, mainframe computers, and supercomputers are the four general categories of computer systems available today. What separates these categories from one another is how much information the computer can store, the processing speed of the system, and the size of the computer system.9

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

Chapter 17 l Computer Technology and Information Security Issues 439

Microcomputers

These are the smallest and least expensive of the four computer categories. Microcomputers are designed primarily for individuals or small businesses. Such systems can fit either on or beside a person’s desktop.10 Within this category are two types of computers: personal computers (PCs) and workstations.11

Personal Computers These machines can sit on a desk, stand on the floor, or are portable, and are either IBM- or Apple-compatible. Both systems can operate easy-to-use programs such as word processing, spreadsheets, and data management programs.12

Non-portable PCs require an AC outlet and weigh more than 20 pounds. These systems do not require special installation requirements (for example, extra air conditioning or heavy- duty wiring). With desktop and floor-standing computers, the user can add circuit boards to the system to add functionality, such as boards for modems, scanners, video capture systems, and fax machines. The following are non-portable PCs:

l Desktops are machines that can fit on a single table or desk. A potential difficulty with this type of system is how much space the cabinet “foot-print” occupies.13

l Floor-standing computers are those in which the system cabinet sits as a “tower” on the floor next to the desk.14

l Luggable systems weigh between 20 and 25 pounds. These systems contain all the components (monitor, computer, and keyboard) in one unit, sometimes including a printer as well. These machines are also called transportable because they are designed to be moved, but not to be used in transit.15

Portable computers do not require an AC outlet. Instead, these machines operate from a battery. Weight for portables ranges from ½ pound to 20 pounds. Portable systems are designed to be used in transit and have no special installation requirements. The following are portable PCs:

l Laptop computers weigh between 8 and 20 pounds. These systems have a flat display screen, which can display mono or color images.

l Notebook computers get their name from their size, which is roughly the size of a thick notebook, and weigh between 4 and 7.5 pounds. These machines can easily be tucked into a briefcase, backpack, or simply under a person’s arm.16 Essentially, notebook computers are a smaller version of laptop computers.

l Sub-notebooks weigh between 2.5 and 4 pounds. l Pocket PCs weigh about 1 pound. These computers are also called hand-helds and are

useful in specific situations. Pocket PCs may be classified as either electronic organizers, palmtop computers, personal digital assistants (PDAs), or personal communicators.17 Personal communicators include smart phones that can function as a video camera, portable media player and an Internet client with email and browsing capability, in addition to providing traditional telephone capabilities.18

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

440 INTRODUCTION TO SECURITY

l Pen computers are often the size of a sub-notebook or pocket computer. These machines lack a keyboard or mouse but allow the user to enter data by writing directly on the screen with stylus or pen.19

l Tablet computers are mobile computers larger than a mobile phone or PDA and integrated into a flat touch screen operated by touching the screen rather than using a physical key board.20 Apple’s iPad is a prime example of a tablet computer.

Although these computers are used at home or during travel, most also have the ability to be used as remote terminals to access company information. Through the Internet, it is not unusual for company employees to access company records and email from home. Given the ability of hackers to access home computers that are “always on” the Internet, security execu- tives need to consider how to protect proprietary systems from well-meaning employees who may need remote access to systems and data.

Workstations Workstations look like desktop PCs but are more powerful. These systems cost between $10,000 and $150,000.21 Essentially, a workstation is a high-end microcomputer.

Minicomputers

Minicomputers make up the middle class of computer size and power. They are popular with small- to medium-size businesses because they can be used as servers and do not require special installation. Servers are central computers that hold data and programs for many PCs or terminals, called clients, which are linked by a computer network. The entire network is called a client/server network.22

Mainframes

Mainframe systems occupy specially wired, air-conditioned rooms and are the oldest category of computers. Mainframe computers are capable of great processing speed and data storage, allowing multiple users to utilize the system simultaneously. Because of their costs (between $50,000 and $5 million), large organizations use these systems, operating them with a staff of professional programmers and technicians.23

Supercomputers

The largest and most powerful computers are called supercomputers. Such computers are high-capacity machines that also require special air-conditioned rooms and specially trained staff. They are the fastest calculating devices ever invented. To achieve this capability, cost (typically from $225,000 to more than $30 million) is set aside to achieve the maximum capa- bilities that technology has to offer. Because of the cost, these machines are used primarily by government, large companies, and universities.24

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

Chapter 17 l Computer Technology and Information Security Issues 441

Networks With increasing numbers of computers in the workplace, employees and employers want to be able to share computer resources. This sharing of resources typically includes proprietary or sensitive data, printers, and other types of applications. Because of this need, networks were developed. A network is just two or more computers connected together.25

Local Area Networks

Local area networks (LANs) consist of two or more computers physically connected with some type of wire or cable (normally coaxial or fiber optic) that forms a data path over which infor- mation is transferred. Communications to a computer on the LAN are instantly broadcast to all the computers connected to the LAN.26

The most popular LAN communication protocols are Ethernet, Token Ring, and ARCnet. The Xerox Corporation developed Ethernet. When using the Ethernet protocol, computers must ensure that there is no traffic on the network before they are allowed to transmit information. IBM developed both the Token Ring and ARCnet protocols. LANs using these protocols pass a special data frame (or token) around the network in a predetermined order to enable data transmission. Under ARCnet, the order of token movement is based on a network address; in Token Ring networks, it relies on the physical placement of devices.27

Because of the way LANs are wired and the protocols they use, communication is limited to a short distance. This is not a major limitation; organizations and businesses have discovered that as much as 80 percent of their communications occur within a limited geographic area. This geographic area is frequently within the same department, office, building, or group of buildings.28

Wireless LANs New technology has led several major organizations to adopt wireless LANs (WLANs). The networks operate on the open air, eliminating hardwire applications and their limitations. While the systems offer added flexibility in connectivity because users are not tied to telephone or other hard lines, they present real problems for those assigned to the protection of assets. The federal government will not allow any government-funded agency to introduce wireless technology until security is improved.

Wide Area Networks It was generally recognized in the 1970s and 1980s that computers in different locations need to talk with one other. This led to the development of wide area networks (WANs). WANs are more powerful networks that can function across wide geographic areas at greater speeds than LANs. Most WANs are connected via telephone lines, although a variety of other technologies, such as satellite links, are used as well. Because telephone lines were used in this system, WANs do not allow multiple computers to share the same communication line, as is possible with LANs.29

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

442 INTRODUCTION TO SECURITY

The Internet For years WANs used the X.25 protocol developed by the Consultative Committee for International Telephone and Telegraph, whereas LANs utilized different protocols. Because LANs communicate with Ethernet, Token Ring, and ARCnet, and WANs use X.25, these networks cannot communicate directly with each other.

The Department of Defense started a network in the 1970s called ARPAnet. This system allowed LANs and WANs to communicate with one another by using a new communications rule called the Internet Protocol (IP) packet. Today ARPAnet has evolved into the Internet, which still uses the protocol developed for ARPAnet.30

IP sends information across networks in packets, with each packet containing between 1 and approximately 1,500 characters, creating two problems. First, most information transfers are longer than 1,500 characters. Second, when data exceeds 1,500 characters, IP breaks the information into packets. These individual packets are then transmitted, which can lead to further problems. Packets can get lost or damaged in transit, or may arrive out of sequence.31

The transmission control protocol (TCP) was developed to deal with the problems of IP. TCP divides the information into packets, sequentially numbers each packet, and inserts some error control information. Each sequentially numbered packet is then addressed to the recipient. IP then transports the information over the network. When the host computer receives the packets, TCP then checks for errors in transmitting. If errors occur, TCP asks for that particular packet to be resent. Once all the packets are received correctly, TCP will use the sequence numbers to reconstruct the original message.32

There are many services available on the Internet. Electronic mail (email) allows individuals to send and receive messages from anyone on the Internet. Telnet allows people to log on to a remote computer and use the resources of that system if they have a valid account. Finger ser- vices allow people to ask for information about a particular user. Usenet is a system of discussion groups in which individual articles are distributed throughout the world. File Transfer Protocol (FTP) allows people to copy or move files from one computer to another. Gophers provide a series of menus from which a person can access virtually any type of textual information. The World Wide Web (the Web or WWW) is a hypertext-based tool that allows people to retrieve and display data. Utilizing both graphics and hypertext (data linked to other data), the Web is one of the most popular tools on the Internet. This is only a sampling of the services provided by the Internet.33

As noted earlier, although the Web has made life easier, it has also brought with it many new problems. Anyone using the WWW is well aware of the spam problem, cookies, and viruses. These are minor problems compared to the possibility that someone could steal your identity by stealing information that you share while online. In the first half of 2006, Symantec reported 2,249 documented new vulnerabilities representing an increase of 18 percent over the previous period and the highest volume of vulnerabilities recorded for any reporting period.34 Five years later (April, 2011), Symantec reported a massive increase in the threat volume to more than 286 million new threats identified in the previous year. This number represents a dramatic increase in the frequency and sophistication of attacks on enterprises.35 It also dem- onstrates how expansive computer usage has become. From government and commerce to personal usage, global dependence on computers and information systems is massive.

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

Chapter 17 l Computer Technology and Information Security Issues 443

The Database Problems There is little doubt that the data (note: within in this chapter the authors will frequently use the terms information and date interchangeably depending upon the context of the situa- tion or description) collected for business has become the backbone of most organizations. Data management resulted in the creation of data management personnel or IT depart- ments. Because data is stored in computers the management and security of these systems has created more problems for security than any other threat in recent years. Some 30 years ago the security department simply controlled access to the computing center, restrict- ing access to only those few who needed to work in the center. Today, control of access is much more complex. The task of safeguarding these assets has many parts. As previously mentioned, the three major aspects include: 1) integrity: making sure that data is changed only in intended ways, 2) confidentiality: making sure that only authorized individuals view the information, 3) availability: making sure the data is available when needed to authorized persons.

But even when proper measures are in place to assure the above, there are still two problems. First, even authorized users sometimes use data improperly (deliberately or accidentally). Second, unknown flaws in policy and its implementation can allow for unintended data access and data changes.

CIOs stress the importance of accountability in maintaining database integrity. This accountability should determine who did what to which data when, and by what means. The CSO generally agrees with this approach. The answer rests in a simple concept: because tech- nical systems are involved in storing data, technical systems must be involved in safeguarding the data. Such a program should do the following:

l Send notification when someone changes data or permissions l Keep a record of all changes to data or permissions l Know what data was changed, when, and by whom l Know who has viewed certain data and when l Generate periodic reports on who accessed certain tables l Investigate suspicious behavior on certain tables l Know who modified a set of tables over a period of time l Automate procedures across multiple servers36

The Need for Computer Security

What is computer security? People normally answer that it is protecting computers and information from some type of theft. While true, this is only part of the answer. Earlier in this chapter we mentioned the need to protect information residing on computers or within infor- mation systems in the context of the confidentiality, integrity and availability of such informa- tion. This too is a form of computer security as it requires protecting access to the computer allowing only authorized persons. Furthermore, computer security must also deal with other hazards such as natural disasters like fires, floods, accidents, and so forth, essentially physically

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

444 INTRODUCTION TO SECURITY

protecting them from harm. In fact, the American Heritage Talking Dictionary defines security as freedom from risks and dangers.37

Unfortunately, the types of crimes committed on a grand scale are often also perpetrated on the small scale. Those computer crimes that startled people a few years ago for their unique- ness and scope are now being mirrored in many communities across the nation.38 According to a Newsweek report, independent hackers account for 82 percent of all Web attacks. Seventy-five percent of the problems are from disgruntled employees; this includes independent hackers. Other attacks come from competitors accounting for between 25 and 35 percent of the prob- lems. Among this group are domestic and foreign corporations and some foreign governments. The number of hacks in 2002 reached 87,000 worldwide with the United States being the big- gest target, followed in number of attacks on Brazil, Britain, Germany, and Italy. By 2010, the number of cyber attacks on United States federal government networks alone exceeded 41,700 out of more than 107,400 reported to the United States Computer Emergency Readiness Team (US-CERT).39 Clearly, cyber attacks continue to be a persistent problem.

According to an American Society for Industrial Security (ASIS) survey, sponsored by the ASIS Council on Safeguarding Proprietary Information, during the period of July 1, 2000 through June 30, 2001, U.S. companies lost up to $59 billion in proprietary information and intellectual prop- erty.40 Furthermore, e-commerce online retailers also suffered losses of more than $2 billion from the cost of purchases made with stolen credit cards (identity theft). By 2010, on-line fraud cost retailers in the United States $2.7 billion.41 Although lower than the $3.3 billion in losses in 2009, on-line fraud continues to be a serious problem. Common types of Web scams are listed below:

l Internet auctions l Shop-at-home/catalog sales l Internet access services l Foreign money offers l Internet info/adult services l Business opportunities l Computers l Web site design42

Classic Methods for Committing Computer Crimes

An initial entry into a business’s computers often requires virtually no expertise. For employ- ees, it is a routine matter, especially if security measures are not used. For nonemployees, it may be as easy as dialing a published telephone number and then using an obvious password such as “system” or “test.” Once connected to the computer, the criminal has a wide range of methods available to disrupt system activity or to observe, steal, or destroy information.

Data Manipulation or Theft Changing data during or after input into a computer system is the simplest, safest, and most common method of committing computer crime. Any size business is vulnerable to it. It can be performed by anyone associated with or having access to the processes for creating,

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

Chapter 17 l Computer Technology and Information Security Issues 445

recording, transporting, encoding, examining, checking, converting, or transforming the data that is eventually entered.43 Data theft has become a major precursor for identity theft. Insiders often sell data files to an individual who then uses the information to “steal” identities. (See the following section on identity theft.)

Salami Technique This descriptive term implies trimming off small amounts of money from many sources and diverting these slices into one’s own or an accomplice’s account. This form of crime is most common in banking environments with a large number of savings and/or checking accounts and automated financial processing. By creating a new program or altering an existing one, an employee can randomly deduct one to five cents from a few thousand different individual accounts. The accumulated sums can then be withdrawn by normal methods from his or her receiving account.44

Trojan Horse Appropriately named after the hollow horse given to the city of Troy, Trojan horse programs initially appear legitimate and will behave as if they were doing what the computer opera- tor expects. However, the Trojan horse contains either a block of undesired computer code or another computer program that allows it to do detrimental things to the system of which the operator is not aware, such as infecting a machine with a virus, worm, bomb, or trapdoor. Remember, a Trojan horse program appears innocent and attracts users by inviting them to load it as some type of software. In reality, Trojan horse programs are not software, but ruses designed to penetrate a computer system so that a program of the penetrator’s choosing can become active.45

Viruses According to the popular press and the world in general, a virus is any hidden computer code that copies itself to other programs. In the computer field, a virus is a set of unwanted instruc- tions executed on a computer and resulting in a variety of effects. In the year 2000 there were over 50,000 known computer viruses.46 By 2008, it was estimated the number of known com- puter viruses stood at in excess of one million.47 The problem appears to be growing exponen- tially. The term virus disruption is used to categorize computer viruses.48

Viruses fall into one of four categories based on the type of damage that the virus inflicts. Innocuous viruses, the first category, cause no noticeable disruption or destruction in the computer system. When humorous text or a graphic message is displayed without causing any damage or loss of data, then a humorous virus (second category) has infected the system. Categories three and four cause damage to the data stored in the computer system. Altering viruses change system data subtly (for example, moving a decimal to a different place, or add- ing or deleting a digit). When sudden widespread destruction of data both on the computer system and on peripheral devices occurs, the machine is possibly infected with the fourth category, a catastrophic virus.49

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

446 INTRODUCTION TO SECURITY

Worms Some people regard worms and viruses as the same type of program. Each has a replication mechanism, an activation mechanism, and an objective. Nevertheless, viruses and worms are very different kinds of programs. While viruses just infect programs, worms take over computer memory and deny its use to legitimate programs.50

Hostile Applets A new danger exists when using the World Wide Web to obtain information. The danger is from so-called hostile applets that utilize a Java-enabled Web browser. Java is Sun Microsystems’ scripting language. Just as viruses perform a variety of tasks without the user’s knowledge, so do hostile applets. The effects can range from mild distraction to data loss.51

Bombs Like the Trojan horse method, a bomb is a computer code inserted by a programmer into legitimate software. There are two types of bombs: time bombs and logic bombs. A date or time triggers a time bomb, whereas some event, perhaps the copying of a file, triggers a logic bomb. There are several advantages to using bombs. The built-in delay makes the program harder to trace. Perpetrators can plan the event for maximum effect, with the delay allowing the bomb to be copied into backup files. Also, some companies implant bombs in their software. If customers fall behind in payments, or if customers attempt to copy the program, the bomb is set off and the program stops or the system is halted.52

Trapdoors and Back Doors Doors allow programmers extensive access to test systems while they are being developed, allowing programmers access that would normally be denied. There are two types: trapdoors and back doors. Trapdoors are intentionally created and are normally inserted during software development. These doors are supposed to be removed once the software is completed. Unintentional access to software code is referred to as a back door.53

Time Stealing This is one of the most common forms of computer crime because people do not consider the cost of accessing a computer without authorization. Any access uses the computer’s resources (hardware, memory, software, peripherals), which cost money. Time stealing is comparable to driving another person’s car without his or her knowledge.54

Electronic Eavesdropping Tapping, without authorization, into communication lines over which digitized computer data and messages are being sent is electronic eavesdropping. By using technologically advanced listening devices, eavesdropping can be done on traditional telephone lines and even satellite transmission networks. If data transmitted are not encoded, capturing and transforming the data is equivalent to using a clandestine tape recorder to record a standard telephone conversation.55

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

Chapter 17 l Computer Technology and Information Security Issues 447

Software Piracy Providing software for computers is big business. Software programs can cost from a few dollars to thousands of dollars. Because of this, some people are willing to copy software and resell it or give it away. This unauthorized copying of copyrighted computer programs is referred to as software piracy. It has been estimated that for each legitimate copy of a software package sold, between 4 and 30 additional copies are made illegally. Although most copied programs are not resold, they deny vendors and software developers’ profits that they should have accrued legally.56

Scavenging Memory Information contained in buffers or random access memory is kept until the space is written over or the machine is turned off. This fact allows a person gaining access to these areas to search for sensitive data that may be left from previous operations.57

War Driving This self-attached term refers to hackers who drive around locating wireless network points of entry. With today’s technology anyone with a laptop and powerful wireless card can enter a company’s wireless network. As the range of the systems increases so do the threats from the war driver.58

Identity Theft Using information stolen from computer databases, criminals are committing criminal acts that impact on the person whose identity is stolen. While using false identification is an old method of criminal activity, the ability to access all types of information on the computer has given this old problem an entirely new life.

Between November 1999 and September 2001, the Federal Trade Commission (FTC) received 94,100 complaints from victims of identity theft. By 2010, Reuters reported some 8.1 million people in the United States were victims of identity theft.59 Complaints show the types of criminal activity as well as the consequences to the victims caused by the identity thief. The following suggests some of the more common losses:

l Cash theft using ATM machines l Electronic check fraud l Denial of credit l Financial service charges for overdrafts l Lost time in dealing with the aftermath l Criminal investigation, arrest

A study by California Public Interest Research Group and the Privacy Rights Clearinghouse reported an average of 175 hours of lost time (over a month of activity) in attempting to cor- rect errors caused by identity theft. Of the reports to the FTC on money losses, 200 individu- als reported losses of between $5,000 and $10,000, with an additional 200 persons reporting losses of more than $10,000. The American Banking Association (ABA) reports that 29 percent

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

448 INTRODUCTION TO SECURITY

($197 million) of its check fraud losses were attributable to identity theft. Two major credit card associations reported to the U.S. General Accounting Office losses of $144.3 million in 2000, up 43 percent from 1996. A 2001 report by Celet Communications projected that losses to finan- cial institutions from identity theft would exceed $8 billion by 2004.60 In January of 2006, a Reuters news report concluded identity theft costs U.S. consumers 4 percent more in 2005 than the $54.4 billion it cost in 2004.61 By 2010, the New York Times reported (February, 2011) the average consumer out-of-pocket cost due to identity fraud increased to $631 per incident, up 63% from $387 in 2009.62

Federal Computer Legislation

The Computer Fraud and Abuse Act of 1986 (CFAA) was the first truly comprehensive federal computer crime statute and was an extension of Federal Statute 18 U.S.C. 1030, enacted in 1984. The CFAA has been amended in 1986, 1988, 1989, and 1990. This law only covers federal interest computers. A federal interest computer is one that is owned, leased, or operated by or for the federal government, contains federally protected information, or is used in interstate commerce.63

This act contemplates six offenses: the unauthorized access of a computer to obtain infor- mation relating to national security with an intent to injure the United States or give advan- tage to a foreign nation, the unauthorized access of a computer to obtain protected financial or credit information, the unauthorized access into a computer used by the federal government, the unauthorized interstate or foreign access of a computer system with an intent to defraud, the unauthorized interstate or foreign access of computer systems that results in at least $1,000 aggregate damage or modifies or impairs medical records, and fraudulent trafficking in com- puter passwords affecting interstate commerce. Penalties range from $5,000 to $100,000 or twice the value obtained by the offense, whichever is higher, or imprisonment from 1 to 20 years or both. These violations are investigated by the FBI’s National Computer Crime Squad (NCCS), which was authorized by the CFAA.64

The Computer Fraud and Abuse Act covers all phases of computer crime including hack- ing, misuse of passwords, and bulletin boards. Electronic trespassers now commit a felony when they enter a federally related computer with intent to defraud. The malicious damage felony violation applies to any hacker altering information in that computer. Preventing other legal users from accessing the computer is also defined as a felony.

The CFAA has a far-reaching new provision regarding electronic bulletin boards. It is now a misdemeanor for any bulletin board operator to provide “any password or similar information through which a computer may be accessed without authorization.” This includes any sharing of information with other board users on how to break into computers.65

Patriot Act Immediately following 9-11 the U.S. government passed the Patriot Act. Part of its mandate deals with computer records and the Internet. Combating identity fraud is one of the act’s pri- mary goals, covered in Title III. Because false identities were found on a number of terrorists

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

Chapter 17 l Computer Technology and Information Security Issues 449

involved in the World Trade Center attack, and the terrorists in financing their efforts used identity fraud, the government has required financial institutions to increase efforts to prevent theft of information that allows for identity theft.66

Computer Systems Protection Security professionals must protect information contained within the computer system from damage or loss. The system might contain any of the following components: an electronic data processing (EDP) center, a LAN, a WLAN, a WAN, or a PC. Regardless of the type of system, the security professional’s dilemma is how to balance convenience in using the system against protecting the system from disasters, systems failures, or unauthorized access. Disaster- recovery planning, identification and access control of software and data, encryption, and physical security are the four facets of computer protection.67

Disaster-Recovery Planning

Disasters such as fires, floods, and earthquakes are potential hazards to essential computer systems. Because these threats are unpredictable, businesses must develop contingency or disaster-recovery plans. Contingency planning requires more than an occasional emergency drill; such plans must cover all business functions, including but not limited to emergency response requirements, personnel resources, hardware backup, software and data file backup, and backup for related and special activities.68

Contingency Procedures Every company should have procedures for dealing with emergencies, whether natural or man-made. Without such planning, the initial response might be a knee-jerk reaction that could lead to people being injured or killed and damage or destruction of data, software, and hardware. To guard against counterproductive knee-jerk reactions, companies must imple- ment contingency planning. Prior comprehensive planning is the first line of defense against all types of disasters.69

Placing the Computer Center. As a rule computer centers should not be in a basement, below grade level, or on first-floor sites. This prevents the entry of surface water into the center. In addition to avoiding areas that are prone to flooding, computer centers should not be placed in sites along known geological fault lines. If this is not possible, make sure that the building is constructed using approved earthquake-proof practices.

Certain areas of any building present problems for security. First-floor sites are most vul- nerable to forcible attack, surreptitious intrusion, civil commotion, or terrorist attack. The top floor also presents opportunities for illegal activities. People can enter the facility through sky- lights or by cutting through the roof.

Ideally, from a security standpoint, computer centers should be within a company-owned area at least 200 feet from the closest public access. If the building houses other types of busi- nesses, then the computer center should be on a floor completely occupied by the company

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

450 INTRODUCTION TO SECURITY

and the floor above and below the site should also be company occupied. If a new site is being selected, the preferred location is either rural or suburban.70

Fire Protection. Buildings housing computer centers should be of noncombustible con- struction to reduce the chance of fire. These facilities must be continuously monitored for temperature, humidity, water leakage, smoke, and fire. Most building codes today require that sprinkler systems be installed.

Remember that water and electrical equipment do not mix. It is preferable to install a dry pipe sprinkler system rather than a wet pipe system. Dry pipe systems only allow water into the pipes after heat is sensed. This avoids potential wet pipe problems, such as leakage. In addi- tion, fast-acting sensors can be installed to shut down electricity before water sprinklers are activated. Sprinkler heads should be individually activated to avoid widespread water damage.

Another type of fire-suppression system uses chemicals instead of water. Once this system is utilized it must be recharged. FM-200 is similar to Halon, which is no longer available, but with no atmospheric ozone-depleting potential. Carbon dioxide flooding systems are also available but should never be used. Carbon dioxide suffocates fire by removing the oxygen from the room. While this effectively extinguishes most fires, it also suffocates people still in the affected area.

All chemical fire-suppression systems are relatively expensive and require long and complex governmental approval to install. Neither chemical fire-suppression system protects people from smoke inhalation, nor can they deal effectively with electrical fires. They are, however, the only fire-suppression systems that do not require computer equipment to be turned off, assuring the quickest possible return to normal operations.

There should be at least one 10-pound fire extinguisher within 50 feet of every equipment cabinet. At least one 5-pound fire extinguisher should also be installed for people unable to handle the larger units. These extinguishers should be filled with either FM-200 or carbon dioxide. None of these agents requires special cleanup.

Install at least one water-filled pump-type fire extinguisher to use for extinguishing minor paper fires. Employees should be trained and constantly reminded not to use water extin- guishers on electrical equipment because of the possibility of electric shock to personnel and damage to the equipment. They should also be discouraged from using foam, dry chemical, acid-water, or soda-water extinguishers. The first two are hard to remove and the others are caustic and will damage computer components.71

Personnel Issues. Crisis management focuses on the swift and effective action of personnel. This means that anyone involved in the emergency response plan must be adequately trained and kept up to date on any changes in procedures. When ranking emergency response proce- dures, protection of life is the most important, followed by protection of property, and finally limitation of damage. One way to verify that employees are familiar with and have current knowledge of the contingency plan is to conduct periodic drills.72

Hardware Backup Most people think contingency planning and hardware backup are the same thing. This is not the case. Hardware backup is only one element of contingency planning. In this phase,

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

Chapter 17 l Computer Technology and Information Security Issues 451

classifying possible disruptions is useful so that hardware backup strategies can be developed. There are three categories of disruptions: non-disasters, disasters, and catastrophes.

Non-disaster disruptions are normally system malfunctions or other failures. Disasters cause the entire facility to be inoperative for longer than one day. Catastrophes entail the destruction of the data-processing facility. In this last category, a new facility must be built or an existing alternate structure must be identified to be used as the computer center.73

Once the extent of the disruption is ascertained, the company must make arrangements for alternate locations in which to conduct their computer operations. Alternative locations are categorized into hot, warm, and cold sites. Hot sites are fully configured and ready to operate within several hours. Warm sites are partially configured but are missing the central computer. Because the central computer is missing, these sites are less expensive than hot sites. However, it may take several days or weeks to locate and install the main computer and any other missing equipment necessary for operation. Once the equipment is installed, these sites can be operational within several hours. The least expensive sites are referred to as cold sites. These locations are ready to receive equipment but do not have any components installed in advance. Cold sites take at least several weeks to become operational.

The major factors in choosing the right “temperature” of the three types of sites are the company’s needs in terms of activation time and cost. All companies must also have a way of alerting personnel of a disruption and telling employees which site to report to for work. Computer personnel must also be trained to operate the hardware at the new site. Finally, the hardware must be compatible with the equipment damaged or destroyed.74

Software and Information Backup Software includes operating systems (for example, DOS, Windows, and Unix), programming languages (C, Pascal, Ada, COBOL, and so forth), utilities (virus checkers, security programs, and batch files), and application programs (word processors, databases, accounting programs, and so forth). Keep in mind that if the hardware at the alternate site is not compatible with the computers at the company, then the software will not operate.

Information and software are both less tangible and more dynamic than hardware. To protect these elements, it is necessary to consider both the physical storage environment and the frequency of change in data. Backing up information and software can protect the company from loss. Regardless of the approach used, backing up data involves copying files onto machine-readable media. The backup media can be tapes, hard drives, CD-R-RW, DVDs, and off-site third-party providers.

Information and software should be stored at on- and off-site locations. Many large organi- zations employ a tiered strategy, using several levels of backups to achieve a balance of safety and convenience. Ideally, a business should have four sets of backup files, with one set of files staying on-site and three sets of files being stored off-site.

On-site files should be housed in a fire-resistant safe designed for computer media. These files are the most recently created backup files until replaced by newer generations. Next, there is an off-site local backup location. This location is normally within a half-mile radius of the computer site. Files at this site are stored in a fire-resistant vault and accessed daily for rotation. Backup files

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

452 INTRODUCTION TO SECURITY

are retained there for one week. Once files leave the off-site local storage facility, then they are moved to an off-site remote location, which is a minimum of 5 miles from the computer center. This site also contains a fire-resistant vault designed for computer media and is accessed weekly. The remote location is used to retain remaining backup files in active use for more than 1 week. Finally, any permanent records that need to be retained for several years are removed to archi- val storage. Archival facilities should be more than 50 miles away from the original computer site. The vault should be fire-resistant and earthquake-resistant. From the security standpoint, as the storage facility becomes more remote, accessibility decreases and security increases.75

Backup for Related and Special Activities Besides protecting computer hardware and software, source documents must be protected. Source documents contain information transformed into machine-readable data from which printouts are generated. The printouts are referred to as either human-readable output or hard copies. This output is used to help in furthering the business activities of the organization. Source documents should be copied or backed up in the event of loss or destruction so that the basic information can be reconstructed in an emergency. Backing up may take the form of duplicate copies, photocopies, microfilm, microfiche, or many other forms of media.76

Identification and Access Control of Software and Data People used to believe that only highly skilled technicians could gain access to computers. This illusion has been shattered by many well-publicized news stories. Today many people believe that any individual possessing basic computer skills can break into a computer system. Because of this perception and the fact that it has occasionally been proven correct, organiza- tions must now go to tremendous lengths to protect their software and data.77

Computer systems can use three methods to determine if a person has a legitimate right to access the system. The three categories are:

1. What a person has: cards, keys, and badges 2. What a person knows: personal identification numbers (PINs), passwords, and digital

signatures 3. Who a person is: physical traits

Each of these authentication methods is designed to make impersonation difficult.78

WHAT A PERSON HAS Some systems require that an employee insert cards, a key, or a badge into the machine before it will allow access to data. Credit cards, debit cards, cash-machine cards, and ID badges are examples of cards. Cards can contain either a magnetic strip or a computer chip. Cards contain- ing a computer chip are referred to as smart cards. With this system, the operator must insert the card before the machine will allow that person to access any information. With a key-lock sys- tem, a person must unlock the computer to use the system. This is one of the most popular types of security features found on PCs. Most PCs have a key-lock installed that allows the authorized user to lock out the keyboard. When the system is locked, keyboard input is not recognized.79

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

Chapter 17 l Computer Technology and Information Security Issues 453

Cards, keys, or badges can be lost, stolen, or counterfeited.80 In addition, the key-locks on PCs can be disabled if a person can remove the case of the machine. This drastic method is seldom necessary, because most PC locks use the same type of key. If someone has a computer with a key-lock, then it is possible that his or her key can open or close the lock on an unau- thorized computer.81

WHAT A PERSON KNOWS PINs, passwords, and digital signatures fall under this category. These security features work with any computer system. PINs work in conjunction with various types of card systems (for example, ATM cards or phone cards). With this system one inserts a card and then enters the PIN, a secu- rity number known only to the user. Passwords are special words, codes, or symbols required to access a computer system. Passwords work in conjunction with access logs. Access logs keep track of who got in, how often they tried to enter, when they entered (date, time, and even location), and when they left, whereas passwords allow an operator into the system. To discourage the misuse of passwords, companies should require passwords to contain at least eight characters that could be any combination of symbols, capital and lowercase letters, and numbers. Easily guessed or obvi- ous passwords should be discouraged. Finally, the company may assign passwords to employees that are meaningless numbers, letters, or both. If the system requires a high degree of security, then a password should only be used once. The last “what a person knows” category, digital sig- natures, is relatively new. This system uses a public/private key system. One person creates the signature with a public key, and the receiver reads it with a second, private key. The “signature” is a string of characters and numbers that a user signs to an electronic document.82

The two biggest pitfalls of the “knows” systems are associated with passwords and PINs. Passwords can be guessed. People have a tendency to use real words or dates (their name, birth date, friends’ or children’s names, user initials, social security numbers, and so forth). Some system operators even fail to replace the default password. PINs and passwords are fre- quently written down by employees in convenient places easily discovered by others.83

WHO A PERSON IS Biometric methods are utilized in this category. Biometrics encompasses the science of mea- suring individual body characteristics. Fingerprints, hand geometry, retinal patterns, voice recognition, keystroke dynamics, signature dynamics, and lip prints are common methods used to identify authorized users. In each of these methods, the computer compares the item being scanned with a copy of the item stored in the computer’s memory. If the compared items match, the computer allows access. If not, the person is denied entry. Biometric techniques are not usually found on PCs because they require expensive equipment to be connected to the computer. This equipment limits mobility, which restricts its use with portable computers.84

Encryption

The best way to protect any type of data is to encrypt it. This also happens to be one of the best ways to protect data on portable machines, like laptop computers. Encryption scrambles the information so that it is not usable unless the changes are reversed. Today there are at least five

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

454 INTRODUCTION TO SECURITY

different methods for encrypting data. Data Encryption Standard (DES) is a 56-bit algorithm. This standard was first published in 1977 and is used to protect federal unclassified information (in this usage, unclassified means sensitive information not falling within the United States Government’s national classification system including confidential, secret and top secret data that requires pro- tection due to national security concerns). Commercial users have adopted it. DES is used in finan- cial applications to protect electronic fund transfers and by the Internet to encrypt information.

In 1978 a 512-bit key was developed that uses the Rivest, Shamir, and Adleman (RSA) algorithm. Another encryption algorithm is Pretty Good Privacy (PGP). Using both the International Data Encryption algorithm (IDEA) and RSA algorithm, PGP is available over the Internet and has become somewhat of a de facto standard for encryption on the Internet.

A new algorithm called Skipjack has been developed by the National Security Agency (NSA) to replace DES. Placed in a computer chip, this algorithm is referred to as a clipper chip. An enhanced clipper chipset is called Capstone. These chips allow law enforcement and other agencies with access to the algorithm key to break encrypted information. The Communications Assistance for Law Enforcement Act (CALEA) preserves law enforcement’s ability, pursuant to court order or other lawful authorization, to access communications and associated call-identifying information. CALEA mandates that law enforcement agencies have the legal right to break encryption algorithms.

One last system, developed but not fully deployed, utilizes both encryption and digital sig- natures to protect email. This system is called Privacy Enhanced Mail (PEM) and uses both DES and RSA algorithms to encrypt email messages.85 In 1996 the U.S. government mandated that all exported data had to be set at 128-bit encryption. Internet Explorer, Firefox, Safari and Netscape are all capable of using 128-bit encryption.86

Physical Security

Physical security places barriers in the path of attackers to deter them from attacking, delay them if they decide to attack, and deny them access to high-value targets should they succeed in penetrating the security system. There are two methods of security planning: traditional planning and strategic planning. Traditional methods start from the outside perimeter and work inward, whereas strategic methods are applied in just the opposite way.87

Electronic Data Processing (EDP) Centers EDP centers have the same physical security needs as any other business or industrial estab- lishments. Most EDP centers use the traditional security approach, beginning with the pro- tection of the grounds around the building, then proceeding to the building’s perimeter, the building’s interior, and the contents of the building.88

With an EDP center, the outer shell provides perimeter protection and includes walls, fences, or partitions. Entrance protection restricts entry points to the EDP center. Doors and other entry points should be restricted to locations essential for safe evacuation in an emer- gency. A receptionist or security officer should be stationed at each entry point during all hours that the department is working.

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

Chapter 17 l Computer Technology and Information Security Issues 455

Compartmentalizing a computer center into clearly defined rooms according to function (control, central processor, test and maintenance, storage, media library, forms, printing, waste) provides additional security. It enables access to each area to be controlled and restricted to authorized personnel. Electronic access control mechanisms such as badge- reading locks should be installed. Badges should only be issued to personnel with a need to be in a given area; badges can also be time-stamped to restrict access to authorized times.

In all circumstances, the computer room should be limited to operations personnel. Protection of these critical areas should follow the principle of “Authorized Access Only.” Only those persons specifically necessary to its operation are allowed into the computer room. This should be the only room where programs, data, and computer equipment are all brought together. Extremely tight control of this room is imperative if the integrity and confidentiality of the data and programs are to be preserved. Installation of intrusion detection devices to monitor these critical areas when not occupied is warranted. These devices are usually wired directly to the department or company security office station to alert, identify, and monitor the location of an intruder.89

Personal Computers Security used to be much easier when we only had EDP centers. These centers were and still are centralized, containing mainframes or supercomputers. Today, there are a multitude of personal computer systems. These systems range from minicomputers to pocket PCs. In addition, many of these stand-alone PCs are connected to either LANs, WLANs, or WANs. Furthermore, the user community is mobile and needs access to ever-increasing online resources.90 Because of this, traditional security methods are inappropriate and inadequate. To protect PCs, the strategic method, where protection starts from the computer and works toward the perimeter, is best.91

A company’s personal computers, like all other corporate computers, should have access limited to authorized users only. If all the computers are in a central location, restrict entry to this area using methods similar to the security measures used in EDP centers.

With LAN and WLAN systems, begin security procedures by locking up everything that can be physically secured. With the strong trend toward concentrating control at hubs, the LAN and WLAN systems become increasingly vulnerable. With LANs make sure that the wiring closets are secured with an appropriate lock system. Another entry point for obtaining data from a LAN system is through the wiring itself. In most companies, the wiring is hidden in the ceiling, walls, or under the carpet, giving a wiretapper a choice of points of entry. All original, necessary wiring needs to be documented and diagrammed. By routinely checking the diagrams against existing wiring, new or suspicious additions will alert security to a potential problem.92 With WLANs problems are even greater. More will be said about protecting these state-of-the art wireless systems later.

For any PCs placed on a person’s desk, a lock-down system attaching the equipment to the desk must be installed. There are four types of lock-down systems: cages, plates, cables, and alarms. These various systems discourage theft of the equipment. Do not neglect to ensure that equipment covers are tamper resistant. Some criminals are now removing computer chips taken from inside computers’ cases and reselling them.93

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

456 INTRODUCTION TO SECURITY

In a similar vein, portable computers have become a popular item to steal. During the Gulf War, a laptop computer was stolen from a military staff officer’s automobile in England. This machine’s hard drive contained detailed plans for Great Britain’s participation in the war. A common scam in many hotels, motels, and airports is for a person in front of an individual with the targeted portable computer to slow the line. If the target puts the notebook computer down, an accomplice standing behind the intended victim picks up the notebook and walks away. The first line of defense against that theft is “street smarts.” This basically means keeping the computer in one’s constant physical possession.94

Besides protecting the computer itself, security must also be concerned with storage media, particularly removable media (discs, tapes, drives, and so forth). People do transport storage media between work and home even if company policy forbids the practice. Memory sticks, flash drives, CDs discs, etc., are small enough to fit into a shirt or coat pocket. Even if the work environment is secure, the home environment is not. Media can also be lost between work and home. If the information contained is sensitive or irreplaceable data or programs, such a loss could be catastrophic. Employees can also alter the data, taking it back to the office where it is used to update the central computer. This incorrect data would then affect the entire organization.95 To help defend against unauthorized downloads of information, some organizations disable USB ports and disc drives on computer systems containing their most sensitive data.

Content Monitoring and Filtering The following discussion is based on an article by D. E. Levine, “Content Monitoring and Filtering,” Security Technology & Design (March 2003): 70–74.

Less than a decade ago, companies paid little attention to monitoring network use, whether LAN, WAN, WLAN, or the Internet. Today, with the widespread use of the Internet, compa- nies cannot ignore looking at who is using the service and what they are doing while on the network. Traditional security wisdom devoted time to monitoring specific types of activity. Unfortunately, experience has shown that traditional solutions are not always effective.

Vulnerabilities due to remote access through the networks fall into several major categories:

l Hacking—These technologically experienced computer users keep finding ways to enter and misuse corporate data and systems.

l Voice systems—The interconnectivity of computers and telephone systems has opened opportunities for computer techies to abuse telephone and voice systems.

l Remote and traveling employees—While the “road warriors” need access to company data and computers, maintaining security while allowing such remote access is a challenge.

l Disgruntled employees—Although not a new threat, the computer provides such employees with new opportunities to strike back at employers.

In a recent survey by the American Management Association, 75 percent of its members reported regularly monitoring employee phone calls, email and Internet use.96 The number one rule in such activities is to inform the employees of the company’s policies. The courts

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

Chapter 17 l Computer Technology and Information Security Issues 457

have ruled that while employers have a right to monitor their own systems, employees have the right to be informed regarding such monitoring activities.

Possible Security Solutions

Traditionally, security has relied on a well-written company policy to enforce access con- trols and handle computer abuse problems. In recent years, monitoring of information has been added to the tools available. However, until recently most of the monitoring was restricted to looking for destructive or prohibited content that entered the company com- puter network. Today security and IT managers are just as concerned about what goes out. Software packages allow companies to block out entertainment, gaming, pornography and other non–work-related sites, while still allowing for Internet access for company-related work. Moreover, many companies have developed policies specifically addressing access to social media sites (e.g., Facebook, Twitter and Myspace). On one hand, companies are using social media sites for legitimate business purposes so allowing access within that context is generally permitted. However, access for personal (non-company business) use is generally prohibited.

Network Security Policy (NSP)

Although this may be old information for some, it is vital that companies have a clear state- ment of network use. The establishment of an NSP is critical in developing other solutions. Employees need to know their rights as well as the expectations of the company. Most NSPs define the problem, set the requirements, discuss solutions, and set out punishment for infractions.

While many NSPs are written from scratch, there are companies that sell model policies that can be modified. In some cases firms or consultants will gladly sell their services to assist an organization in the development of these policies.

Appropriate Use Policy (AUP)

Closely allied to the NSP is the AUP. This document aids the NSP by clearly delineating what the company believes is appropriate use of company computers, software, networks, and email.

Virus Scanning

Most computer users are at least familiar with the concept of scanning for viruses. Some form of antivirus software should protect every computer system or stand-alone computer. As noted earlier, there are thousands of virus threats every year, making it almost impossible for the end user to keep current. There are a number of companies providing virus-scanning soft- ware. Among these are: McAfee, Symantec, Computer Associates, Panda, and Trend Micro. It is important to remember that, while these programs are generally effective, no developer can claim to be 100 percent effective because new viruses appear regularly.

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

458 INTRODUCTION TO SECURITY

Email Filtering Software

Because of problems noted earlier, such as spam, email filtering software has become com- mon in many company security programs. Both CSOs and CIOs are interested in this type of software, just as they are with the solutions discussed above. Most of the commercial software allows the end user to set rules or protocols that mail must meet. When the email fails to meet criteria it is blocked. Some of the more popular vendors include:

l IM Message Inspector (www.elronsoftware.com) l Email Filter (www.surfcontrol.com) l Imira Screening (www.ulead.com) l Mailwasher (www.mailwasher.net) l Eblaster 3.0 (www.spectorsoft.com) l Eudora (www.eudora.com)

Web Monitoring Software

Just as the email software allows for monitoring and blocking of email that fails to meet cer- tain criteria, the Web monitoring software allows the end user to monitor what Web sites employees are using and for how long. Some software allows the user to filter or restrict access to certain sites. Many schools use this type of software to block pornographic and other adult content Web sites from their systems.

Some of the more popular vendors in this area are:

l Websense (www.websense.com) l IM Web Inspector (www.elronsoftware.com) l Surfcontrol Web Filter (www.surfcontrol.com)

Spam Filtering

Some authorities estimate that between 50 percent and 70 percent of the email received each day is spam. This may be one of the biggest problems, or more accurately annoyances, associ- ated with Web use. This specialized email filtering software blocks email based on key words, sender’s address, mail content, or other specified criteria. Vendors include the following:

l Spam Killer (www.mcafee.com) l Spam Assassin (spamassassin.org)

Computer Forensic Investigations

Another tool in combating a variety of computer crimes is investigations. There are individuals, primarily consultants, who specialize in forensic investigations associated with computer crimes. These individuals are often self-taught computer users from the public law enforcement sector, security, or IT.

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

Chapter 17 l Computer Technology and Information Security Issues 459

These experts can trace email, viruses, and other computer transactions. When the “I Love You” virus was trailed, it led investigators to the Philippines and the originator. Investigators have traced mails from bomb threats, as well as viruses. The investigator follows the trail using information stored in the receiving computer to post offices that handled the transmis- sion. Investigators commonly use tools such as Whois or Better-Whois. These database search engines look for databases of registrars that record online users and their Internet Protocol (IP). Ultimately, the investigator finds the initiating machine. The next step is to determine who used the machine at the time the message was drafted.

Unfortunately, the tracing is usually not this easy because most computer users know methods to send false trails. Spoofing, or making the email appear it is from someone else, is common. Re-mailing is also designed to cause investigators additional grief. Stealing email accounts is another means of protecting the criminal’s identity. It would be nice if there was always an easily followed audit trail, but the reality is that smart programmers find ways to get around security protection. It takes time for the investigator to discover these new techniques.97

As noted earlier in this chapter, the use of WLANs is expanding. As these wireless systems, with their advantages, become more widespread, CIOs and CSOs are challenged to protect the information that is transmitted over the airwaves. Tools currently available to detect unauthor- ized access to the WLAN include vulnerability scanners (software) such as Ping and other well- known network discovery technologies. These software packages can detect points of access, but will not identify the perpetrator. However, point of access information is vital to security efforts, since hackers need open ports to operate.

Dealing with Identity Theft From a security position, the recent increase in identity theft presents unique problems. Identify theft is defined as using the identity information of another person to commit fraud or engage in other unlawful activities. Criminals are stealing identities by raiding the databases of legitimate company customers. The schemes may be old-style or high-tech. For example, a simple theft of personal information by a help-desk worker resulted in thousands of individual identity thefts by accomplices. The worker used his position at a credit-checking firm to access credit reports. The worker sold the credit reports to accomplices, who then sold the social security numbers and names of the individuals to identity thieves. In another scam, an iden- tity theft ring placed a cohort as a temporary employee at a company’s world headquarters. The employee, using access codes needed for work, accessed executive records. With social security numbers, names, and birth dates, the ring obtained credit cards. When apprehended the ring had charged more than $100,000 to the cards. In yet another case, an employee of a major insurance firm stole 60,000 personnel records, selling them over the Internet. A simple ad announced the sale of thousands of names and social security numbers. The going price for an individual identity can be less than $100. The bottom line is that personal information is only as safe as the company securing it.

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

460 INTRODUCTION TO SECURITY

What do identity thieves do with the information? Among other things the following are their most frequent activities:

l Open new credit card accounts l Take over existing credit card accounts l Apply for loans l Rent apartments l Establish services with utility companies l Write fraudulent checks l Steal and transfer money from existing bank accounts l File bankruptcy l Obtain employment using the victim’s name

Organizations can no longer ignore this problem. The number of victims has become too great and the federal government has taken an interest in protecting citizens’ personal information.

What to Do?

The proper action depends on the level of potential victimization. Companies need to find ways to protect the information that they gather, whether company information or private client information. Users/customers need to know what to do if and when they become victims.

Safeguarding Corporate Information

John May, consultant and author specializing in identity theft, makes the following recommendations:

l Properly dispose of personal information. These documents should be shredded. l Conduct proper background checks on all individuals with access to personal information. l Limit the number of temporary agencies working within your organization. l Develop guidelines on handling personal information. l Train the staff on information security. l Limit the use of social security numbers. Don’t use social security numbers on

identification cards, time cards, or paychecks. l Control access to personal information to those who have a legitimate reason for access. l Secure personal employee information in locked files or with proper password access or

through file encryption. l Implement and enforce password security measures. l Change passwords on a regular basis.

Protecting Your Identity

John May also has suggestions for protecting your own identity. While there are no totally fail- safe programs, the following will reduce personal risks.

l Invest in a personal shredder. Shred all personal information, credit card statements, cancelled checks, preapproved credit card offers.

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

Chapter 17 l Computer Technology and Information Security Issues 461

l Purchase a mailbox with a locking mechanism. l Review your monthly bills promptly. l Order a copy of your credit report at least once each year. (There are three major credit

bureaus—TransUnion, Experian, and Equifax.) l Keep a record of all your accounts—numbers, expiration dates, telephone numbers, and

addresses. l Opt out of preapproved credit card offers by calling 888-567-8688. l Minimize the amount of information you carry in your wallet or purse. Don’t carry a social

security card. l Cancel any seldom used cards. Limit the number of cards you use. l Don’t leave outgoing checks or paid bills in your residential mailbox. Take them to the post

office.

Much of the preceding information is from Johnny R. May, “Feeling Vulnerable? Corporate and Personal Identity-Theft Protection Procedures,” Security Products (March 2003): 30–31.

When You Are the Victim

The FTC recommends the following should you become a victim of identity theft:

l Contact the fraud departments of the three major credit bureaus to report the theft of your identity. Ask that a fraud alert be placed on your file and that no new credit be authorized without your personal consent.

l Contact the security department of those organizations where your accounts have been accessed. Close those accounts. Put passwords on any new accounts.

l File a report with the local police. Get a copy of the report for your own protection, showing the date and time the theft was reported.

The FTC has created a simple fraud affidavit that can be sent to all financial institutions to alert them of the potential of fraud from stolen identities.

Education/Training

Companies should educate employees about the problem of identity theft, how to prevent it and what to do if victimized. Orientation opportunities should be conducted until all employ- ees understand the significance of the problem to individuals and the company. Awareness can be increased through traditional techniques such as posters, brochures, or booklets. The use of email alerts is also encouraged.

Other Data Resource Vulnerabilities While the focus of this chapter has been on computers, there are other company assets that may also present vulnerabilities to data theft. Sharp Electronics reports that many IT and security managers did not recognize the potential risks associated with copiers, faxes, and scanners. Survey results indicate that 77 percent of the respondents did not know that copier/printers

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

462 INTRODUCTION TO SECURITY

contained a hard drive. Sixty-five percent said that copiers/printers presented little or no risk to data security.

What most users, including security and IT personnel, do not realize is that document information in these devices remains in memory until memory needs eventually overwrite the data. Peter Cybuck, Senior Manager, Business Development, Sharp Electronics Corp., suggests the following to provide proper security for these vulnerabilities:

l Limit access to copy/print/fax/scanners to authorized users only. l Install network-based software to monitor use and flag abuse. l Protect your devices from hacking by using secured network interfaces. l Automatically erase document data. l Protect confidential information from accidental or intentional viewing and distribution.98

CRITICAL THINKING What problems are created when a company decides that laptop computers are a better option for employees than desktop versions? What are the advantages of such a program as well as potential pitfalls?

Summary The world of computers and the information that is stored, processed, analyzed, and dissemi- nated by them are constantly changing. With change come vulnerabilities. While the progress achieved in this dynamic field has improved the general state of the world, there are always those who use the technology for personal gain or criminal activity. The CIOs, CISOs, and CSOs must work together to protect the companies and the individuals that they serve.

Review Questions 1. Why is it safe to assume that computer crime will increase in the years ahead? 2. What are some of the vulnerabilities unique to computer systems? 3. What are LANs? What are WLANs? 4. What significance does the term password have in the area of computer security? 5. What is the World Wide Web (WWW)? 6. How are LANs, WLANs, and the WWW security issues? 7. What are some of the management principles basic to computer security?

References [1] See <http://en.wikipedia.org/wiki/Biometric>. Biometrics (ancient Greek: bios = “life”, metron = “mea-

sure”) is the study of methods for uniquely recognizing humans based upon one or more intrinsic physical or behavioral traits.

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

Chapter 17 l Computer Technology and Information Security Issues 463

[2] Covington PA. In: Computers: the plain English guide, 3rd ed. Jackson, MI: QNS Publishing; 1991.

[3] CBS Evening News, FBI’s New Data Warehouse A Powerhouse; August 30, 2006.

[4] From Wikipedia, the free encyclopedia; See: <http://en.wikipedia.org/wiki/Reed_Elsevier>. [5] Fischer RJ, Green G. In: Introduction to security, 6th ed. Boston: Butterworth-Heinemann; 1998.

[6] Ware and Lorraine Cosgrow. The survey: what you have to say. CIO Magazine; April 1, 2003, downloaded 4/2/2003, <www.cio.com/archive/040103/results_content.html?printversion=yes>.

[7] See: <http://www.cio.com.au/article/360432/cio_spending_priorities_shifting_gartner/>. [8] Carroll JM. In: Computer security, 4th ed. Boston: Butterworth-Heinemann; 1996. [Cobb, Covington]

[9] Sawyer SC, Williams BK, Hutchinson SE. In: Using information technology: a practical introduction to computers and communications. Chicago: Irwin; 1995.

[10] Clontz Covington, Rothman S, Mosmann C. In: Computer uses and issues. Chicago: Science Research Associates; 1985.

[11] Sawyer, Williams, Hutchinson.

[12] Covington, Sawyer, Williams, Hutchinson.

[13] Sawyer, Williams, Hutchinson.

[14] Ibid.

[15] Covington, Sawyer, Williams, Hutchinson.

[16] Ibid.

[17] Sawyer, Williams, Hutchinson.

[18] See: <http://en.wikipedia.org/wiki/IPhone>. [19] Sawyer, Williams, Hutchinson.

[20] See: <http://en.wikipedia.org/wiki/Tablet_computer>. [21] Sawyer, Williams, Hutchinson.

[22] Covington, Rothmann, Mosmann, Sawyer, Williams, Hutchinson.

[23] Covington.

[24] Covington, Sawyer, Williams, Hutchinson.

[25] Amoroso E, Sharp R. In: PCWeek: Intranet and Internet firewall strategies. Emeryville, CA: Ziff-Davis Press; 1996. Cobb Covington, Hahn H, Stout R. In: The Internet complete reference. St. Louis: Osborne McGraw- Hill; 1994. Levine DE. Local area network security. In: Hutt AE, Bosworth S, Hoyt DB, editors. Computer security handbook 3rd ed. New York: John Wiley and Sons; 1995. p. 22.1–22.21.

[26] Amoroso, Sharp, Cobb, Covington, Levine. Local area network security.

[27] Amoroso, Sharp, Levine. Local area network security.

[28] Amoroso, Sharp, Cobb, Covington, Levine. Local area network security.

[29] Amoroso, Sharp, Covington, Hahn, Stout, Levine. Local area network security.

[30] Amoroso, Sharp, Hahn, Stout, Krol E. In: The whole Internet: users’ guide and catalog. Sebastopol, CA: O’Reilly and Associates; 1992.

[31] Amoroso, Sharp, Krol.

[32] Hahn, Stout, Krol.

[33] Hahn, Stout.

[34] Symantec Report; Dtd. September 25, 2006, Vulnerabilities in Desktop Applications and Use of Stealth Techniques are on the Rise, Cupertino, Calif.

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

464 INTRODUCTION TO SECURITY

[35] Symantec Corp., Internet Security Threat Report, Vol. 16; See: <http://www.symantec.com/about/news/ release/article.jsp?prid=20110404_03>.

[36] Mazer MS. Data access accountability: who did what to your data when? A Lumigent, Data Access Accountability Series, White Paper, Lumigent Technologies, Inc.; 2002, downloaded 4/4/2003, <www. lumigent.com>.

[37] American Heritage Talking Dictionary, SoftKey, 1996.

[38] Boni WC, Kovacich GL. In: I-way robbery. Boston: Butterworth-Heinemann; 1999. p. 28.

[39] InformationWeek, Federal Cyber Attack Rose 39% in 2010: See <http://www.informationweek.com/news/ government/security/229400156>.

[40] See: <http://www.asisonline.org/newsroom/pressReleases/093002trends.xml>. New York, N.Y. (September 30, 2002).

[41] See: <http://ecommercejunkie.com/2011/01/18/online-fraud-losses-decline-in-2010/>. [42] The Dark Side of the Internet. Newsweek, March 17, 2003: special insert.

[43] Clontz, Magel, Schweitzer.

[44] Clontz, Magel.

[45] Carroll, Clontz, Levine DE. Viruses and related threats to computer security. In: Hutt AE, Bosworth S, Hoyt DB, editors. Computer security handbook, 3rd ed. New York: John Wiley and Sons; 1995. p. 19.1–19.24. Simond F. In: Network security: data and voice communications. New York: McGraw-Hill; 1996.

[46] Computer virus information: See: <http://www.cknow.com/cms/vtutor/number-of-viruses.html>. [47] See: <http://www.prlog.org/10814398-number-of-known-computer-viruses-exceeds-1-million.html>. [48] Carroll, Clontz, Dunham K. Introduction to viruses, <www.iste.org/~iste/antivirus/intro.htm> Levine.

Viruses and related threats; Sawyer, Williams, Hutchinson, Simond; 1996.

[49] Clontz, Levine. Viruses and related threats.

[50] Clontz, Levine. Viruses and related threats, Simond.

[51] Clontz, Hoffman H. Hostile applets: the dark side of Java. Comput Shopper, October 1996:80.

[52] Carroll, Clontz, Levine. Viruses and related threats; Sawyer, Williams, and Hutchinson, Simond.

[53] Clontz, Levine. Viruses and related threats.

[54] Clontz, Magel.

[55] Ibid.

[56] Clontz, Rothman, Mosmann.

[57] Kabay ME. Penetrating computer systems and networks. In: Hutt AE, Bosworth S, Hoyt DB, editors. Computer security handbook, 3rd ed. New York: John Wiley and Sons; 1995. p. 18.1–18.55. [Schweitzer]

[58] Mattox M. Worried about wireless? Secur Prod, February 2003. [30+] [59] See: <http://wsau.com/news/articles/2011/feb/08/id-theft-down-28-percent-in-us-in-2010-survey/>. [60] Green link: the threat of terrorism and the role of financial institutions. Secur Prod, February 2003:38–41.

[61] See: Reuters news report, January 31, 2006, Identity theft losses grow; Web a small factor, <http://news. com.com/Identity+theft+losses+grow,+Web+a+small+factor/2100-1029_3-6033610.html>.

[62] See: <http://bucks.blogs.nytimes.com/2011/02/09/the-rising-cost-of-identity-theft-for-consumers/>. [63] Carroll, Clontz, Rasch MD. Legal lessons in the computer age; 1996, <www.securitymanagement.com/

library/000122.html>. [64] Carroll, Clontz. Federal bureau of investigation national computer crime squad; 1996, <www.fbi.gov/

compcrim.htm>.

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

Chapter 17 l Computer Technology and Information Security Issues 465

[65] Clontz, Magel.

[66] Mattox.

[67] Sawyer, Williams, Hutchinson.

[68] Clontz, Hutt AE. Contingency planning and disaster recovery. In: Hutt AE, Bosworth S, Hoyt DB, editors. Computer security handbook, 3rd ed. New York: John Wiley and Sons; 1995. p. 7.1–7.35. [Sawyer, Williams, Hutchinson]

[69] Clontz, Hutt.

[70] Carroll, Clontz.

[71] Carroll, Clontz, Platt FN. Computer facility protection. In: Hutt AE, Bosworth S, Hoyt DB, editors. Computer security handbook, 3rd ed. New York: John Wiley and Sons; 1995. p. 12.1–12.24.

[72] Carroll, Clontz, Hutt.

[73] Clontz, Hutt.

[74] Clontz, Hutt, Sawyer, Williams, Hutchinson.

[75] Clontz, Hutt.

[76] Ibid.

[77] Clontz, Sawyer, Williams, Hutchinson, Walsh ME. Software and information security. In: Hutt AE, Bosworth S, Hoyt DB, editors. Computer security handbook, 3rd ed. New York: John Wiley and Sons; 1995. p. 14.1–14.20.

[78] Clontz, Kabay, Sawyer, Williams, Hutchinson.

[79] Bologna GL. Computer crime and computer criminals. In: Hutt AE, Bosworth S, Hoyt DB, editors. Computer security handbook, 3rd ed. New York: John Wiley and Sons; 1995. p. 6.1–6.31. [Clontz, Kabay, Sawyer, Williams, Hutchinson]

[80] Kabay.

[81] Clontz.

[82] Carroll, Clontz, David JR. Security for personal computers. In: Hutt AE, Bosworth S, Hoyt DB, editors. Computer security handbook, 3rd ed. New York: John Wiley and Sons; 1995. p. 21.1–21.21. Hoyt DB. Security of computer data, records, and forms. In: Hutt AE, Bosworth S, Hoyt DB, editors. Computer security hand- book, 3rd ed. New York: John Wiley and Sons; 1995. p. 15.1–15.24. [Kabay, Sawyer, Williams, Hutchinson]

[83] Clontz, David, Hoyt, Kabay.

[84] Clontz, Kabay, Sawyer, Williams, Hutchinson.

[85] Clontz, Freeh LJ. Impact of encryption on law enforcement and public safety (June 26, 1996), downloaded 7/25/1996, <www.fbi.gov/congress/encrypt/encrypt.htm> Levine. Viruses and related threats. Rothfeder J., Hacked! Are your company files safe? PC World; November 1996:170–82. Simond, Sussman V. Policing cyber- space. U.S. News & World Report. January 1995:55–60.

[86] Determining your browser and encryption level. http://cgi.scotiabank.com/simplify/browser.html

[87] Clontz, National Crime Prevention Institute. In: Understanding crime prevention. Boston: Butterworth- Heinemann; 1986.

[88] Clontz, Fischer, Green, National Crime Institute.

[89] Magel.

[90] Clontz, Simonds.

[91] Clontz, National Crime Institute.

[92] Clontz, Simonds.

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.

466 INTRODUCTION TO SECURITY

[93] Carroll, Clontz, David.

[94] Carroll, Clontz, Stone.

[95] Clontz, Simonds.

[96] Moses J. Checking Employees’ Phone, Email and Internet Usage, National Federation of Independent Business E-News; April 03, 2003, downloaded 4/4/2003, <www.NFIB.com>.

[97] Poole T, Hansen J. Tips for tracking the E-Mail trail. Secur Manage; January 2001:42–7.

[98] Cybuck P. Machine talk. Secur Prod; March 2003:34.

Fischer, R., Halibozek, E., & Walters, D. (2012). Introduction to security. ProQuest Ebook Central <a onclick=window.open('http://ebookcentral.proquest.com','_blank') href='http://ebookcentral.proquest.com' target='_blank' style='cursor: pointer;'>http://ebookcentral.proquest.com</a> Created from apus on 2020-08-16 13:13:21.

C op

yr ig

ht ©

2 01

2. E

ls ev

ie r

S ci

en ce

& T

ec hn

ol og

y. A

ll rig

ht s

re se

rv ed

.