October 23, 2009

October 23, 2009
Word of the Day
Overheard in the Tech Blogosphere:
"I suspect that a sizable percentage of small botnets are those developed by people who understand or are operating inside a business as employees or by criminal entities that have dug deep and gotten insider information...We've seen a growth in the number of sites that offer the sale of corporate documents that were extracted from the bots." - Gunter Ollmann
> Word of the Day: micro-botnet
A micro-botnet, also called a mini-botnet or baby botnet, is a small network of Internet-connected computers that have been hijacked to attack specific companies or individuals within a company. Micro-botnets are often used in corporate espionage. Typically, the bots will monitor the enterprise network to identify key individuals and assets and target them for attack. The bots are used to seek out information like financial authentication passwords or data that can be sold to competitors.

Because there are usually fewer than one hundred computers to control in a micro-botnet, attackers can fine-tune an exploit to circumvent an enterprise intrusion detection system (IDS) or firewall. A successful micro-botnet infiltration often depends on social engineering because it's much easier to gain access and hide a small botnet's activities when the attacker has legitimate credentials. Red flags indicating the presence of a micro-botnet include new spikes in an individual's normal traffic patterns or quickly accelerating rights in a specific end user's permissions.

> According to Gunter Ollmann, VP of research at Damballa, small botnets account for 57 percent of all botnets.

Secret Word of the Day
This is a synonym for bot. (Hint: You might dress up as one for Halloween.) What's the secret word?

Acronym Challenge
KBA is an authentication scheme where the user is asked to answer at least one "secret" question during an online registration process. What does KBA stand for?

Tech Trivia
What popular Web-based site for transferring money was attacked by a botnet put together by former security administrator John Schiefer? (And yes, he's in jail!)

Writing for Business
We need to assign seating for the security seminar so _________ by next Friday.
b. please RSVP
Which is correct?

Get more out of your security event log data
Your network has plenty to say about your organization's threat posture. These three tips will help you get the most out of security log management tools.
Thwarting insider threats
Five simple measures you can take to protect your organization from insider attacks.

