Technology Nightmare: How to Protect Your Network from the Threat of Rogue IT Employees

An IT admin for the City of San Francisco holding the network hostage is just the latest high-profile example of the security risk posed by insiders. Learn what steps you can take so it won't happen to your company.

CONNECTIONS
City of San Francisco
Phaseit
Fri, July 18, 2008CIO Terry Childs, a network administrator for the City of San Francisco is accused of creating a super-password on the switches and routers in the city's Fibre WAN and using it to block everyone else's access to administrative functions. According to reports, Childs had been detected tampering with the network and had reacted with hostility when disciplined after a confrontation with a supervisor.

As a result of Childs' alleged actions, administrators are unable to access the routers and switches, although the network continues to function. Childs was charged with four counts of computer tampering and held on $5 million bail.

A week after the incident the city still hadn't gotten access, and details were still sketchy. However a few things are obvious.

"This should never have happened in an organization of this size," Cameron Laird says flatly.

The need to protect organizations from rogue employees existed long before computers were invented, notes Laird, the vice president of Houston, TX, security consultancy Phaseit. "There are principles people have been working out for a couple of millennia," Laird says. "I think we're best off working from models that enjoy more experience than we do in IT. For instance accounting and auditing where we've got a few hundred years experience." Some of those principles, like access control, have been incorporated into IT culture. Some, like least privilege are only beginning to be widely incorporated. Some, like dual authorization, haven't made it into the culture yet.

Unfortunately in the Childs case, many of those principles were apparently ignored. Reports of the incident indicate that while the city was routinely logging administrative activity on the network, they failed to act quickly and decisively when they found the first signs of Childs' activities.

Best practice in these situations is to immediately deny access to the system pending a review. For example, the Nuclear Regulatory Commission's rules for nuclear power plants require that access to important systems be immediately revoked if any suspicious activity is detected.

Another problem is that the city apparently did not effectively apply the principle of least privilege. A network administrator obviously needs wide-ranging access to the system being administered, but that is not the same as unquestioned, unrestricted access. Childs apparently had the ability to create a super password and alter other administrator's privileges at will. While his activities were logged, logging amounts to locking the barn door after the horse is stolen.

In theory, employees at any level should be granted only those privileges absolutely needed to do their job. Since this requires a separate set of privileges for everyone but the lowest ranking employees, this is usually impractical. As a result we tend to assign employees to groups with the same privilege levels, whether that specific employee needs all those specific privileges or not.


Loading...
Network MarketSpace
Thinking About Deploying Mobile Broadband?
Explore lessons and best practices experienced by companies that have deployed mobile broadband to their workforce. Learn more »
Increase Application Performance and User Experience
This research shifts the attention from basic load-balancing features to application delivery features. Learn more »
Gartner Magic Quadrant, Application Delivery Controllers 2009
The market for products to improve the delivery of application software over networks remains dynamic. Learn more »
McAfee's Network Security Platform IPS
McAfee's Network Security Platform IPS; the costs, benefits, flexibility, and risk elements. Learn more »
The Cost of SQL Sprawl
Learn how a new approach to SQL server consolidation can reduce server counts by 50%, lower maintenance costs by 70% and reduce administration time by 75%. Learn more »
A Bottleneck-free Infrastructure
Storage bottlenecks have a significant impact on performance and productivity. Learn more »
Application Delivery Despite Emerging Challenges
IT organizations need to choose appropriate application delivery solutions that can scale to support the emerging challenges. Learn more »
 
SPONSORED LINKS
 

ROI of Application Delivery Controllers

Upgrading to VMware vSphere with vWire

Maximizing website Return on Information with high-quality search

See how AT&T can help protect your network.

Webcast: Unleashing the Power of Customer Data

White Paper: Improve Agility with Operational Responsiveness

White Paper: Legacy Tools: Not Built for the Helpdesk

Taking a Seat at the Executive Table: The Reality of Virtualization

White Paper: Next Generation Remote Infrastructure Management

Keeping Your Members Safe from Online Scams and Predators

The Total Economic Impact of Network Security Intrusion Prevention

Generation Remote Infrastructure Management - Changing the Paradigm

Cloud-Based Email Management: Opinion Shifts In Favor

eBook: How Can You Make Your People Productive Anywhere?

Achieving Business Agility with Application Grid

Ready to virtualize tier one applications? Check your virtualization maturity.

Seven Ways ITIL Can Help You in an Economic Downturn

Tips for successful virtualization management.

AT&T Synaptic Storage as a Service. Expand on demand

Trend Micro ranked #1 against real-world malware. Read more.

Webinar: Jump-start your in-house e-discovery with Ringtail QuickCull from FTI Technology

Streamline IT Costs. Boost Performance with WAN Optimization.

Build your 1st app FREE with Force.com

TDWI checklist helps define data readiness for analytics. Download report.

eZine: A Roadmap to Reducing IT Complexity

Gartner Magic Quadrant, Application Delivery Controllers 2009

Return on Information: Google Enterprise Search pays you back

Cut Costs & Green Your IT Operations with PC Power Management

White Paper: 4 Customer Service Myths

White Paper: Managed Security for a Not-So-Secure World

White Paper: 5 Best Practices for Smartphone Support

Global Research: CIOs Weigh In On Virtualization

5 Key Virtualization Management Challenges

Secure Email and Web-Based Communication from Evolving Attacks

WagerWorks Takes Fraudsters Out of the Game using iovation

Seven Design Requirements for Web 2.0 Threat Protection

Increase UPS efficiency without sacrificing protection.

Learn how advanced forecasting tools can deliver significant business results for global corporations.

Lower IT Costs with Oracle Database 11g Release 2

White Paper: Visibility and the New Normal of Mobile Work

Taking the Service Desk to the Next Level

Learn about The Information Technology Infrastructure Library.

Return on Information: Google Enterprise Search pays you back. Get the facts.

VMware. The source for Business Infrastructure Virtualization.

ShoreTel tells businesses to untangle from competitors' complexity and turn to its brilliantly simple UC solution

Top Five CIO Challenges

Read the RSA report: Security for Business Innovation

64-page prescriptive guide to security, compliance, and IT operations.

A Clear View Toward Virtualization

Virtualization Technology as a Business Solution

 
 
RESOURCE CENTER