Case Study: network servers

Case Study:

An auditor was hired to determine if he could gain access to the network servers of a printing company that contained important proprietary information. The chief executive officer (CEO) of the printing company boldly proclaimed that breaking into the servers by the auditor would be “next to impossible” because the CEO “guarded his secrets with his life.” The auditor was able to gather information about the servers, such as the locations of the servers in different printing plants and their IP addresses, along with employee names and titles, their e-mail addresses, phone numbers, physical addresses, and other information.

The auditor also learned that the CEO had a family member who had battled through cancer and lived. As a result the CEO became involved in cancer fundraising. By viewing the CEO’s entry on Facebook, he was also able to determine his favorite restaurant and sports team.

The auditor then called the CEO and impersonated a fundraiser from a cancer charity that the CEO had been involved with before. The auditor said that those individuals who made donations to this year’s charity event would be entered into a drawing for prizes, which included tickets to a game played by the CEO’s favorite sports team and gift certificates to area restaurants, one of which was the CEO’s favorite.

After stoking the interest of the CEO in the fake charity event, the auditor said that he would e-mail him a PDF document that contained more information. When the CEO received the attachment he opened it, and a backdoor was installed on his computer without his knowledge. The auditor was then able to retrieve the company’s sensitive material. (When the CEO was later informed of what happened, he called it “unfair”; the auditor responded by saying, “A malicious hacker would not think twice about using that information against you.”)

Pretend that you are an employee of that company and that it is your job to speak with the CEO about the security breach. What would you say to him? Why?

Student one post:

If I had to speak to the CEO about the security breach, I would first bring up the importance of not being naïve about the potential threats that could affect their organization. I would stress the importance of security, not to take it lightly, and expect the unexpected because if a real attack happened, it could potentially cripple the company and loose its public image.

I would then stress how easy it was to gain access to this information: A simple call or visit to the printing plants could reveal server locations, and scanning these systems could release employee information. In addition, I would mention how easy it is to get personal information from a person’s social networking site and use that information against them by processes of “vishing”, impersonation, and concealed malware that could be opened in email attachments to ignite a malicious attack.

I would also bring up that policies should be reworked, employee awareness should be heightened, and more audits should be made to continuously check the system to expose any potential vulnerabilities and risks.

Write here your response to student one post (1/2 page):

I agree that the issue of naivety is significant in the security of any organization. You could also ask the CEO to ensure all his employees have intensive training on security. Such training would minimize security breaches in the firm. The entire human resources of this organization need to protect its personal information from anyone. They should keep such information to themselves to avoid vulnerability to any malice, even their workmates.

The idea to check the security system at frequent intervals is sensible. It allows the CEO of the company to determine any faults when they occur. It also ensures that there are minimal loopholes for anyone who wishes to have illegal access.

I disagree on reworking of policy because it has limited effectiveness. It depends on the nature of the policy about company security. The CEO could change to policies that are riskier than current ones. This means that he/she should test new policies before any possible implementation.

Pretend that you are an employee of that company and that it is your job to speak with the CEO about the security breach. What would you say to him? Why?

Student Two post:

Clearly the CEO suffered a shot to his ego as a result of the audit, but I would point out that the auditor did exactly as he was asked. He tested the current system and identified vulnerabilities before any malicious outside source was able to find and exploit them. I would focus on benefit the audit provided to the company and explain how the audit results will allow the company to improve security before something catastrophic occurred.

I would like to include the auditor in the conversation if at all possible to determine how he was able to access the information and what information he was able to access. I think that including the auditor allows the company to identify the obvious vulnerabilities and provides a good place to begin revising (or creating) the security plan.

I would insist on better security for information regarding servers, which would probably come from better employee education regarding sensitive information. I would suggest that private or sensitive information be placed on servers that are not available directly to the Internet/WAN, but instead placed behind a series of firewalls as part of the LAN. I would also suggest that employees be better informed about opening attachments and clicking links that could be malicious.

The security policy should also include methods for continuous monitoring for the network and servers to detect abnormal usage or activity. If the company had appropriate system monitoring, it is likely that they would have been able to detect the auditor attempting to breach the system.

Write here your response to student two post (1/2 page):

It is unnecessary to include the auditor in this discussion because the CEO already knows about the trick. I agree that the CEO was over-confident in himself. You could explain to the CEO that a perfect security system does not exist. Malicious hackers invest in expensive trainings to hack such security systems. This suggests that CEO should be willing to learn new methods of protecting the organization.

The suggestion to shift sensitive information from the internet could result in other problems. The internet is extremely significant in the storage of such information. What the CEO could do is to increase any protection on the internet. Any server that is available to the internet needs installation of extra access codes.

The CEO should change the folder name that has information on the employees. Instead of labeling it “Personal Information”, he/she could use a different title. This will confuse any hacker who accesses their systems. The hacker will probably search for the commonest name for the folder, and not find it.

What recommendation would you make for training and awareness for the company?

Student one post:

To start, I would review, and if necessary, rework or add any policies and procedures that pertain to personnel and company security. I would then make sure everyone would be aware of these policies and procedures, having them review them often, and understand any changes, and stress that if they have any questions to ask.

After reading the document, it seems that several psychological approaches were made to gain access to the system. Therefore, I would send a companywide email or memo reminding people about outside threats and basic safety. This memo should be sent regularly so that security is never pushed away and forgotten.

This memo would include never releasing personal information or passwords or accessing, opening, or downloading random or suspicious links, files, or documents. I would also mention how easy it is to access personal data through social networking sites, and to keep as much information about themselves as private as possible, to not just ensure company safety, but their own individual safety as well. I would also ensure that access to all sites is limited to those who have business being there by implementing a plan, such as key cards to cut down on site access.

Finally, I would offer a short seminar or class pointing out some general security threats, and some common signs of an attempted attack. This would not be too in depth, but just enough to get employees thinking about the importance of security and what steps they can do to help enforce it.

Write here your response to student one post (1/2 page):

I disagree on the suggestion that the seminars should not be in depth. There must be intensity in addressing all these security issues. Hackers keep inventing new methods of accessing respective company information. E-mails or memos are not effective because some employees could ignore them. It would be effective to meet the employees instead of writing to them. Employees will understand the significance of the entire security issue. The seminars should be frequent and, educate all employees on diverse possible attacks.

I agree that there must be deliberate encouraging of employees to seek clarifications on security. This will ensure that existing policies are effective. There should also be the establishment of rules that make employees not to be careless. Such rules will reduce any vulnerability to attacks that the human resources could face.

What recommendation would you make for training and awareness for the company?

Student twopost:

I think that the key to good security is educating employees. I would recommend a training program for all employees that would include information about social engineering attacks, phishing, software and firmware updates, monitoring, response, and personal information security.

I would make sure the employees understood the dangers of social engineering attacks and that awareness and attentiveness could be the difference between avoiding a breach or not. I also think that as part of the training on social engineering, employees should be educated about the threat of phishing attacks and the importance of securing personal information (specifically on social networking sites).

Another important factor to security is making sure that software and firmware is updated. I think that many people take this act for granted, but a failure to update software could lead to a breach. Specifically, the updating of antivirus and anti-malware programs is essential to being able to detect threats.

I would also stress the procedures for monitoring the systems for breaches and how to response if a breach occurs to avoid or mitigate the impact of the event.

Write here your response to student two posts (1/2 page):

I consent with all the proposals in this response. Employee education on security is significant because it allows them to fight any attacks. Inclusion of the aspects in the response is extremely effective. Firmware updates enable employees to determine attacks before they mature. This is a protective technique because it secures company information.

Companies need to get genuine supplies of their respective anti-virus. Extremely malicious hackers could liaise with anti-virus suppliers in breaching company security. Installing any anti-malware program, should be consistent but diverse. This means the installation should be by different programmers each time there is an installation. This reduces any predictions that could compromise company security.

The threat on social engineering is real in contemporary organizations. Employees need to avoid revealing sensitive information of social sites. They should understand the significance of denying access to strangers. The CEO could demand proper identification of the fake fundraiser personnel.

Latest Assignments