RE: Are sophisticated attacks just FUD?

From: Steve Hall (steve_at_tarkie.net)
Date: 06/30/04

  • Next message: Joshua Berry: "RE: Are sophisticated attacks just FUD?"
    To: "'Sam Heshbon'" <sheshbon@yahoo.com>, <focus-ids@securityfocus.com>
    Date: Wed, 30 Jun 2004 08:44:09 +0100
    
    

    I doubt all the firewall logs between you and the Internet will stop the
    potential for Internal Hackers (disgruntled employee's) from attacking your
    systems.

    I forget the stats, but its somewhere in the region of 70% of hacks are from
    an internal source.

    Don't allow him to underestimate the impact of worm/virus attack getting on
    your internal networks too, the ability to detect and respond to a threat
    quickly is part of your defence, not a nice to have.

    Regards

    -----Original Message-----
    From: Sam Heshbon [mailto:sheshbon@yahoo.com]
    Sent: 29 June 2004 17:12
    To: focus-ids@securityfocus.com
    Subject: Are sophisticated attacks just FUD?

    I had a big discussion with my boss who claims most of the IPS, SIM and
    other new tools are just a
    hype protecting from sophisticated threats, which only exist in labs.
    He thinks multi staged attacks and so on do not often happen in the wild and
    shows our firewall's
    logs as evidence. It is true we see mostly worms.(NMAP) scanning happens
    once in a while, but he
    claims it's a script kiddy and the fact we have never seen a breach means it
    is not a real threat
    (we run a large network operation).
    I'm looking for statistical data showing how frequent sophisticated attacks
    and advanced tools are
    evolved and what there damage is to the corporate. If anyone knows of a
    research showing if this
    is FUD or a real problem, I'd love to prove him wrong (I'm willing to admit
    I'd be happy to have
    some new toys ;)

            
                    
    __________________________________
    Do you Yahoo!?
    New and Improved Yahoo! Mail - 100MB free storage!
    http://promotions.yahoo.com/new_mail

    ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------


  • Next message: Joshua Berry: "RE: Are sophisticated attacks just FUD?"

    Relevant Pages

    • Risks Digest 25.28
      ... Internet attacks against Georgian web sites ... How reliable is DNA ...? ...
      (comp.risks)
    • Re: Dubious distinction for Estonia (part 2)
      ... there are going to be fights on the Internet," said Hillar Aarelaid, the ... or ethnic Russian sources in retaliation for the removal of the statue. ... The Estonians note that an Internet address involved in the attacks ... staggering the biggest Estonian bank and overwhelming ...
      (soc.culture.baltics)
    • Cyber Warfare
      ... Defences against cyberwarfare are still rudimentary. ... Yes-unless the attacks came over the internet. ... hackers out of important government computers. ...
      (soc.culture.china)
    • Re: [Full-disclosure] Internet attacks against Georgian web sites
      ... Shadowserver and others have been following the botnets attacking the Georgians web sites, and that is confirmed as happening. ... So--it is clear their web sites are under attack, and that Internet visibility-wise, the impact is real for the Georgians. ... such attacks are nothing but routine here in Israel. ... When I ran the defense for the Israeli government Internet operation and then the Israeli government CERT, ...
      (Full-Disclosure)
    • Re: Finding multi-homed, internet connected, systems as potential point-of-entry.
      ... It uses ICMP and may or may not work depending on how the local network is set up. ... that are able to directly connect to the internet ... -Detect for the response of this message on the spoofed address at the ... Cross site scripting and other web attacks before hackers do! ...
      (Pen-Test)

  • Quantcast