News

Other articles

Sunday 14 March 2010
Article  Cloud security assessment scheme launched

Sunday 14 March 2010
In Brief  Human element undermines encryption

Thursday 11 March 2010
Article  Digital privacy framework steps closer?

Monday 8 March 2010
Audio Podcast  Web 2.0 and Social Networks in the Enterprise

Sunday 7 March 2010
Article  Digital Economy Bill raises privacy concerns

Wednesday 3 March 2010
Article  Cloud security threats identified by CSA

Tuesday 2 March 2010
In Brief  Vote for your CSO Interchange topics

Thursday 25 February 2010
Article  Cloud Computing : a simple question of supplier risk

Monday 22 February 2010
Article  Most dangerous coding errors outed

Monday 22 February 2010
In Brief  Microsoft IE users to get browser choice update

Friday 19 February 2010
Article  Google Buzz fail highlights privacy expectation rise

Thursday 18 February 2010
In Brief  Annual hacking challenge aims for mobiles and browsers

Wednesday 17 February 2010
Audio Podcast  The Challenges of Cross Border eID

Monday 15 February 2010
Audio Podcast  The Readiness of eID in Europe Part 2

Sunday 14 February 2010
Audio Podcast  The Readiness of eID in Europe Part 1

Remote Working and Pandemics May Open Organisations Up to Further Breaches

A Pandemic Situation Will Create A Hacker's Paradise
Written by Ben Chai (SecurityVibes.com)
Published on Monday 11 May 2009
1 comment(s) | Subnetwork United Kingdom
 

As corporations struggle to come to grips with a potential pandemic or a delayed epidemic of swine flu in Autumn/Winter. Further issues regarding the brokeness of the security of remote working must be thought about.

Many companies use remote workers and indeed have based their pandemic contingency plans on remote working. However there are many potential problems in a pandemic situation as reported in our podcast interview with Dr Nigel Brown.

However for the purposes of this article, let’s assume that the infrastructure is strong enough to cope with all the students and remote workers using bandwidth and servers. There is now another more technical issue that needs to be assessed. Wifi security is broken. In a pandemic situation, a car could park outside your house and listen in to your network.

The vulnerable component in your network is the home hub. This does not have the capabilities of the corporate switch where you have virtual one to one points between every computer. Instead all traffic on the hub can be listened to. It doesn’t matter, if you change the admin name and password on the hub, it doesn’t matter if you only allow specific MAC addresses to connect, it doesn’t matter if you enable WEP or WPA encryption, it doesn’t matter if you are using VPN over an IPSEC encrypted tunnel. The hub is and always will be a vulnerable point where tech savvy hackers can intercept and listen to traffic and ultimately capture critical passwords.

A pandemic situation where people are forced to work from home is a hacker’s paradise as hacker’s can now target the houses of senior executives knowing exactly where they live and just wait until they log on to the corporate network. Over time, they will have built up enough information to log on as that executive themselves and access confidential data on the system or worst install rootkits across your corporation for further access or to use corporate systems as part of a botnet army.

In addition to the hackability, there is the whole issue of management of anti-virus, application and operating system updates to a remote workforce's systems as commented on by Mark Stanhope in a previous article. Without these critical updates, users workstations can be compromised and potentially used as part of a botnet to attack corporate systems or even to mount an attack on other organisations.

A pandemic situation can truly create a hacker's paradise!

What Can Organisations Do To Mitigate This Attack Vector?
There is actually not much organisations can do to mitigate this attack vector unless it is to have all employees live in detached houses with alarms that resound when anyone parks within wifi range of their employees houses.

Remote working is open to compromise. This article could equally have been about user incompetence, ignorance or laziness instead of the technical reasons discussed. As a result companies must make a risk assessment and do their utmost to reduce data on the home system.

More technological defences could be employed on corporate servers but they are inadequate once a hacker has access to a user’s session.

Finally wherever possible use a laptop mobile device for internet connectivity. This allows corporate laptops to connect directly to the internet without the need for the home hub. The downside of this is that uploads are very slow (eg if an employee needs to email a large file), however they work perfectly fine when receiving information, using VoIP and sending keystrokes.

For further reading and listening:
How to sniff hubs and hack WEP and WPA from tech.blorge.com
More techniques to hack WPA from tech.blorge.com
List of top ten mobile broadband devices
Security Vibes Dr Nigel Brown on the Problems of Pandemic Contigency Plans
Security Vibes Reputational and Brand Damage caused by Pandemics
Security Vibes How Technology Can Spread Swine Flu
Security Vibes Swine Flu - A Potential Business Risk

Remote working has a number of user and technological vulnerabilities and must be assessed in terms of acceptable risk appetite, the main trade off being keeping the business functional in times of pandemic situations.

Our members have posted 1 comments about this article. Only members can view and submit new comments.
Related contents
Advertising
Related Questions & Answers
Companies
Most commented
Most Popular
+
 
Related companies
Securityvibes.com (9 fans)
Read members opinions and rate Securityvibes.com too !
Ratings  0
Trend Micro
Read members opinions and rate Trend Micro too !
Ratings  0
Loglogic (1 fans)
Read members opinions and rate Loglogic too !
Ratings  0
Hermitage Solutions
Read members opinions and rate Hermitage Solutions too !
Ratings  0
Beeware (2 fans)
Read members opinions and rate Beeware too !
Ratings  0
Search
Our RSS Feeds
Subscribe to our RSS feeds for free !
Social Web