Rapid changes in technology have made it tough for banks retailers and other companies that hold on databases of consumer information to act up with the latest Internet crime tactics.
For Cleveland-based Third Federal Savings & Loan the solution was simple: It hired hackers to try to change its Web place before any bad guys got the come about.
This business of “ethical hacking” or “penetration testing” has become commonplace among financial institutions and major corporations over the past six years. But increasingly companies of all types and sizes are hiring security experts to act desire the enemy.
“There’s always been people breaking into Web sites,” said Chris Wysopal an expert in information security. “But now there’s much more of a criminal element. It’s gone almost commercial.”
Wysopal was move of a group that gained notoriety for publishing software flaws in well-known programs and operating systems in the mid-1990s. He began working in information security in 1999 and started his own tighten. Veracode in Burlington. crowd. that offers an automated service that points out computer-security flaws for businesses.
He said today we’re seeing a new breed of more dangerous hackers. In the past it was teen vandals who sabotaged Web sites for kicks. Now more people are breaking into company for profit.
The most famous inspect was in 2005 when hackers stole at least 45.7 million customer credit- and debit-card numbers from TJX which owns T. J. Maxx. Marshall’s. domiciliate Goods and A. J. Wright.
Well-publicized security breaches desire that one which happened because of weak security on the company’s internal wireless access have put other companies on the alert.
Sam Bowne who teaches a class on ethical hacking at the City College of San Francisco said it’s about measure. He said most companies “thoughtlessly displace their data at assay because they don’t understand how bad it would be if it got stolen.”
Ken Stasiak president of SecureState a Cleveland tighten that specializes in ethical hacking said it’s easier to become an Internet bad boy today than ever before - with a marketplace of how-to information and hacking tools available online.
“It’s getting to the point where if you have basic computer and networking knowledge you could certainly wreak some havoc on a company that has its guard down,” said Jose Granado principal of security and technology solutions at Ernst & Young.
He heads the professional-services company’s team of 30 ethical hackers that works out of its Advanced Security Centers in New York and Houston.
Granado said every large firm like his offers such services and smaller specialized firms are popping up all over the are probably five to seven times more firms doing this now” than in 2001 when he founded Ernst & Young’s security centers. Granado said.
Bowne said education in penetration testing is just starting to change state more common. He knows of only six other American colleges that offer courses in it.
Stasiak who had worked in security services at Ernst & Young and other large firms was quick to recognize the niche was growing. So in 2001 he founded SecureState.
His aggroup members don’t just cut into company computers via the Internet. They also communicate to employees to see they ordain hand over sensitive information and sneak into corporate offices to try to get information from internal computers.
“You can have the beat firewall but if I can walk in your lie door and act your server then it isn’t doing much good,” Stasiak said.
Forex Groups - Tips on Trading
Related article:
http://www.redv.net/2007/11/04/ethical-hackers-hired-to-act-like-the-bad-guys/
comments | Add comment | Report as Spam
|