m 9
424 CHAPTEF| 1ct lnformation Systems Security
Using the collaboration IS you built in Chapter 2 (page Z4), collab_ orate with a group of students to awwer thefollowing questions.
The purpose of this activity is to assess the current state of computer crime.
l0-4. Search the Web for the term computer crime and. any related terms. Identi$r what you and your team_ mates think are the five most serious recent examples. Consider no crime that occurred more than 6 months ago. For each crime, summarize the loss that oc_ curred and the circumstances surrounding the loss, and identi$r safeguards that were not in place or were ineffective in preventing the crime.
l0-5. Search the Web for the term computer crime statistics and find two sources other than the ponemon surveys cited in Q2, a. For each source, explain the methodology used
and explain strengths and weaknesses of that methodology.
b. Compare the data in the two new sources to that in Q2 and describe differences.
c. Using your knowledge and intuition, describe why you think those differences occurred.
Hitting the Target On December 18,2013, Target Corporation announced that it had lost 40 million credit and debit card numbers to attackers. Less than a month later Target announced an additional 70 million customer accounts were stolen that included names, emails, addresses, phone numbers, and so on.
After accounting for some overlap between the two data losses, it turns out that about 98 million customers were at_ fected.2o That's 31 percent of all 3tB million people in the United States (including children and those without credit cards). This was one of the largest data breaches in U.S. history.
These records were stolen from point_of_sale (pOS) sys_ tems at Target retail stores during the holiday shopping
I O-6. Go to http : / / ww w. p on emo n. org/ tib rary / 20 1 3 _ co s t_ of_ data-breach- glob al- analysis and dovrmload the 2013 report (or a more recent'report if one is available). a. Summarize the survey with regard to safeguards
and other measures that organizations use. . b. Summarize the study,s conclusions with regard to
the efficacy of organizational security measures. c. Does your team agree with the conclusions in the
study? Explain your answer.
l0-7. Suppose that you are asked by your boss for a summary of what your organization should do with regard to computer security. Using the knowledge of this chapter and your answer to questions l0_4 _ 10_6 above, creaE a PowerPoint presehtation for your summary. presentation should include, but not be limited to: a. Definition of keyterms b. Summaryofthreats c. Summaryofsafeguards d. Current trends in computer crime e. \iVhat senior managers should do about
security f. What managers at all levels should do about
puter security
season (November 2Z to December 15, 2013). If you r shopping at a Target during this time, it,s likely your data lost. Below is a short summary of how attackers got away 'that much data.
l-{ow DidThey Do lt? The attackers first used spear-phishing to infect a third-party vendor named Fazio Mechanical Services frigeration and HVAC services).2l Attackers placed a of malware called Citadel to gather keystrokes, login dentials, and screenshots from Fazio users.2z The att^, then used the stolen login credentials from Fazio to ac
20Ben Elqin' aThree NewDetails fromTarget's credit card Breac hi BuslnessweeN March 26,2014, accessed fu ne 4,2or4, www.businessweek.com/gllllnryt! 4l:?tt/ thrce -new-detaits-froil_ t"rs"t a;ALcard_bieari.
;Wffii;r;trfrffi:;ifr::":l;:^X:*tr#t: Kebsonsccuritv.com'FebruaryB,2014, accessed \ne 4,2o14, http://krebsonsecurity.
'rcfuis Poulin' \lhat Retailere Need to Learn from ihe irrgei Data Breach topmtect Against SimilarAtracksi, security Intelligence, Ianuary 31, 2014,accessed Iune 4 2o74, http://securttyinaltigence.*i/-ir$t-ur*in:;;;;;;;;;;;;mihr-attacks-retaiters/#.u44ptptducs.
Case Study 10 425
Attackers Malware Writers
3. Phishing Malware
4.Stolen Credentials
5.Stolen Credentials &
Malware
9.Stolen Data
t.
2. Malware
Fazio Mechanical Services
I ll
#
10. Stolen Data
Drop Servers
Russia, Brazil'
and Miami
a^ *OFIgUre e[J* lo ltrkget Data Breach
tqundor portal (server) on Target's network' The attackers es-
rualated privileges on that server and gained access to Target's
li,mremal network.
Once in, the attackers compromised an internal Windows
ffitre server. From this server the attackers used malware named
Itr[mjan.POSRAM (avariant of BlackPOS) to extract information
lffiom POS terminals. BIackPOS was developed by a l7-year-old
from St. Petersburg, Russia, and can be purchased from under-
pound sites for about $2,000'23
The customer data was continuously sent from the POS ter-
minalstoanextractionserverwithinTarget,Snetwork'Itwas tliaen funneled out of Target's network to drop servers
in Russia'
ffirazil, and Miami. From there the data was taken and sold on
ffie black market.
litre Darnage
For the attackers, the "damage" was great' It's estimated that
trhe attackers sold about 2 million credit cards for about $26'85
each for a total profit of $53'7 million'2a Not bad for a few
weeks of work. Incentives for this type of criminal actMty
are substantial. Payoffs like these encourage even more data
breaches.
thrget, on the other hand, incurred much greater losses
than the hacker's gains. Target wilt be forced to take a loss on
all of the merchandise purchased using the stolen credit cards'
It will also have to upgrade its payment terminals to slrpport
chip-and-PlN enabled cards (to prevent cloning cards from
stolen intbrmation), pay ilrcreased insurance premiums' pay
legal fees, settle with credit card processors' pay for consumer
creclit monitoring, and pay regulatory lines'
Target faces a loss of customer confidence and a drop in its
revenues (a 46 percent loss for that quarter)' furalysts put the
clirect loss to Target as high at $450 million'26 The company lost
its CIO Beth lacob ana paia its CEO Gregg Steinhafel $16 mil-
lion to leave'26 ThedatabreachaffectedmorethanjustTarget.Credit
unions and banks will spend more than $200 million is-
*4, ,"* cards.Z7 Consumers will have to enroll in credit
7....uo*l.',,dnl*ut,.,lackP0SN{alw.areI.IsertinTargetDaraBreachDeve|opedbyl7.Year.oldRussianHackerlTheHackerNews,Ianuary|7'20l4'
ffi:Tn;:*i*,.i;l3#*:fftrffiKi**i,iiyJ#ffit1',,.,iyfl',:fififfi1li;';:::::###i1,,4,hnp:/ikrebsonsecuri,v com/2014/05/
:.t - t ar Eel- hreach - by' lhe -n umh ers'
-:Bruce Horor.itz, ,,Data Breach rakes Toll on
,rarget profit l, usA Today,February 26, 2014, accessed lune 6, 2014, ututwusatoday'com/story/money/
,tr^,,ff'#"rf##' Al:;ir;::::1,'ilti*1fli.:;, rcerrsecurity.com, February tB,2or4,accessed tone 4,2or4, www'fierceitsecuritv'com/story/
wvet-bre ach - I i m e line / 20 I 4 -02- I B' t-Ie;t;:;ih; i"rget Breach, bv the NumbersJ'
Target's Network
Vendor Server
426 CHAPTEF| 1o lnformation Systems Security
monitoring, continuouslywatch their credit, and fill out paper_ work if fraudulent charges appear on their statements.
Insurance premiums for organizations other than Target will probably go up as well. Insurers may believe that more data breaches like this will occur in the future. Insurers will demand higher premiums, stricter controls, and more system auditing from organizations.
Just like car accidents, data breaches may not be viewed as important until after they occur. The data breach affected Target enough that it's upgrading its infrastructure, changing internal systems, and looking for a Chief Information Security Officer (CISO).28
Will there be a more severe. data breach in the future? Probably. Are organizations ready for it? Based on past perfor_ mance, we won't be ready for it until after ithappens.
GIUESTIClNSi
l0-8. \iVhy did the attackers spear_phish a contractor to Target?
l0-9. Explain how a third-party contractor could weaken an organization's overall security.
l0-10. Describe how data was stolen from Target. l0-ll. How might a data loss at one organization affect other
organizations?
lO-12. Explain why large organizations are attractive targets for attackers.
lO-f 3. \rVhymight chip-and-pin cards reduce this type of theft? f 0-f 4. \Ahy didn't Target have a CISO before the data breach?
'Thrget Taps an outslder to Reramp IT security After Massive Ha cki' Businessweek, April29,20l4, accessed lu ne 4,20t4,'com/articlzs/Za1444-29/tary6'tuins-to-an-outsider-foi-cio-bob airoa"i-ti-r"ii*[-it-securrty-after-massiue-hack.
MyMlSLab- Go to mymislab.com forAuto-graded writing questions as weil as the foilowing Assisted-graded writing questions:
l0'15. Suppose you need to terminate an emproyee who works in your depaftment. Summarize security protections you must take. How wourd you behave differ- ently if this termination were a friendly onel
I 0'I 6. Read about MapReduce and Hadoop on pates 365-356 of chapter 9 if you have not already done so. ls MapReduce suitable for password cracking? Explain your answer.Assume that it is. rf it takes 4.5 years for one compurer to crack a password, how rong wiil it take r0,000 computers to crack one using Hadoopl rf it takes 2 miilion years to crack a password, how rong wiil it take 10,000 computers to crack one? What does this teil you about password construction?