Hacking
By: Jon • Essay • 455 Words • November 11, 2009 • 886 Views
Essay title: Hacking
Companies fear the public relations and share-value impact of disclosing a security breach. Perversely, revealing even an unsuccessful attack can be a public relations disaster. And once an organization announces that it has been attacked, it may suffer further attacks as a result of the news coverage.
For other crimes, we can use police statistics or insurance claims data to measure the change in risk over time. Currently, however, there isn't much of a market for cyberinsurance, so insurance data isn't available. Police data isn't much better because companies are hesitant to report computer crimes. Some distrust the police, believing them to have a low level of awareness of computer security issues. Laws like the Freedom of Information Act and the low rate of successful prosecutions add to this distrust.
But companies can't hide everything. The highest-profile attacks in the current environment are Web site defacements. A useful resource in this area is Attrition.org's Web site. Hackers notify this group when they deface a site, and Attrition.org makes a mirror copy of it as a record. This means it has accurate data reflecting trends in this area. And the current trend isn't good. Attrition.org's Web site is seeing about 30 defacements per day, an increase from 13 per day a year ago and two per day two years ago. And it doesn't look like this will improve anytime soon.
To supplement this data from the outside world, we also regularly examine data from our systems to ensure that our defense is properly focused. We have an intrusion-detection sensor outside the firewall that logs many attacks, and we also