Tuesday, May 4, 2010

Cyber-terrorism Statistics

Today I would like to share some statistics about Cyber terrorism which have been occurred around the world. So, I would like to share some information about clients who are at risk of Cyber terrorism attacks and then I’ll explain more about unauthorized system entry and cost of Cyber terrorism.

First of all I intend to mention about the persons or organizations that are at risk of any attacks. Most feel that military installations, power plants, air traffic control centres, banks and telecommunication networks themselves are the most likely targets. Other targets include police, medical, fire and rescue systems, which could be hurt, along with Wall Street, water systems. So according to the various kind of victim that exists in cyber terrorism we can classify attacks as below graphic shape.

Cyber terrorism does not have to come from the average hacker or even online terrorists. The Govt. carried out a series of its own attacks on itself, in order to test its own defences against online-based attacks.

After identifying possible Victim and presenting simple statistic in above graph I intend to explain a bit more about unauthorized system entry.

How common is unauthorized system entry?

A survey conducted by the Science Applications International Corp. in 1996 found that 40 major corporations reported losing over $800 million to computer break-ins. An FBI survey of 428 government, corporate and university sites found that over 40% reported having been broken into at least once in the last year. One third said that they had been broken into over the Internet. Another survey found that the Pentagon's systems that contain sensitive, but unclassified information, had been accessed via networks illegally 250,000 times and only 150 of the intrusions were detected. The FBI estimates that U.S. businesses loose $138 million every year to hackers. According to the CIA in the past three years government systems have been illegally entered 250,000

Costs of cyber-terrorism

As a final part for this post it is better to know more about cost of cyber attacks According to a source in Great Britain, terrorists have gained at least up to 400 million pounds from 1993 to 1995 by threatening institutions. Over the three years, there were 40 reported threats made to banks in the U.S. and Britain. In January of 1993, three separate incidents took place in London. During the sixth, a brokerage house paid out 10 million pounds after receiving a threat and one of their machines crashed. On the fourteenth incident, a blue-chip bank paid blackmailers 12.5 million pounds after receiving threats. Another brokerage house paid out 10 million pounds on the twenty-ninth incident. Some terrorists just take money, rather than resorting to blackmail. A Russian hacker, for example, tapped into Citibank's funds transfer system and took $10 million.


Saturday, May 1, 2010

How Data Centers Handling Cyber Terrorism

In previous posts I’ve mentioned about what Cyber terrorism is and explained about different kind of attacks which clients may face with them. Also I’ve described some defensive strategies of prevention from Cyber terrorism.

Yesterdays I was reading a true story about Data centers which exist in all on the world that keep and serve requested information of their clients. Data centers everyday try to serve their clients in a better manner in terms of accessing to information accurately and in a short time.

So in this post I intend to explain more about data centers and their exposure to any cyber terrorism attacks which may happen for data inside this data centers.

Recently, a survey was conducted by data center provider Digital Realty. It revealed that most of the data centers are in expanding mode in the next 2-3 years. They also found out of 300 North American Companies surveyed that 83% plan for data center expansions in the next two years because they need more power.

The recent AFCOM (leading association of data center) survey of 400 data centers revealed that only one-third have considered cyber terrorism as part of the disaster recovery plans, only one-quarter have policies and procedures manuals in place for cyber terrorism, and only one-fifth provide cyber terrorism employee training. Also, end users are keeping close eye on data centers because they are demanding more. They realized how important data centers are and they cannot do good business without them. Customers also expect that the performance of data center never fails or slows down.

There are different technologies and approaches that can be effective against cyber terrorism for Data centers:

1. Physical security: physically breaching the weak security of a data center is far easier for an attacker with little or no technical know-how. So it is extremely important to set-up multiple layers of physical security around your data center to encounter any act of cyber terrorism.

2. Recruit well-trained security personnel: The first layer of security of a data center is having a batch of efficient security personnel deployed at strategic locations. Care must be taken to recruit well-trained security personnel from a reputed security agency

3. Access control systems: The entry point of the data center should have the most stringent access control systems in place to prevent any unauthorized intrusion. There are generally three types of user authentication mechanisms:

ü unique individual passwords like a PIN

ü a tangible document that belongs to the user, like an ATM card or an ID card

ü Biometric authentication based on measurable, unique, physical characteristics of an individual, like fingerprint, voice recognition, face recognition, hand geometry, vascular patterns, retina scan etc.

In conclusion I would like to mention that Security of data in our data center is critical not only for our business but also for overall security of individuals. If data regarding customers in an organization is available to criminals, then this data can be used for identity theft for camouflage. If compromised information is financial in nature then this could fund terrorists.