Free Newsletter
Register for our Free Newsletters
Access Control
Deutsche Zone (German Zone)
Education, Training and Professional Services
Government Programmes
Guarding, Equipment and Enforcement
Industrial Computing Security
IT Security
Physical Security
View All
Other Carouselweb publications
Carousel Web
Defense File
New Materials
Pro Health Zone
Pro Manufacturing Zone
Pro Security Zone
Web Lec
ProSecurityZone Sponsor
ProSecurityZone Sponsor
ProSecurityZone Sponsor
ProSecurityZone Sponsor
ProSecurityZone Sponsor
ProSecurityZone Sponsor

Surveyed hackers predict winter peak in criminal activity

Tufin Technologies : 26 August, 2009  (Technical Article)
Hackers surveyed at Defcon 17 reveal their activity cycle with fewer hacks performed during the summer holidays than over the winter period
Enjoy the rest of your summer vacation say the hacking community, as you're far less likely to be targeted now than during your Christmas and New Year vacation. That's according to the results released by Tufin Technologies, a provider of Security Lifecycle Management solutions, who have released the findings of its "Hacker Habits" survey conducted amongst 79 hackers at the annual gathering of hackers at Defcon 17 in Las Vegas this month. Eighty nine percent of hackers admitted that IT professionals taking a summer vacation would have little impact on their hacking activities, as a whopping 81% revealed they are far more active during the winter holidays with 56% citing Christmas as the best time to engage in corporate hacking and 25% naming New Years Eve.

"It's received knowledge in the security world that the Christmas and New Year season are popular with hackers targeting western countries," said Michael Hamelin, chief security architect, Tufin Technologies. "Hackers know this is when people relax and let their hair down, and many organizations run on a skeleton staff over the holiday period."

If you want to know when you should be most on your guard it's during weekday evenings with 52% stating that this is when they spend most of their time hacking, 32% during work hours (weekdays), and just 15% hacking on weekends.

Ninety six percent of hackers in the survey said it doesn't matter how many millions a company spends on its IT security systems, it's all a waste of time and money if the IT security administrators fail to configure and watch over their firewalls. Eighty six percent of respondents' felt they could successfully hack into a network via the firewall; a quarter believed they could do so within minutes, 14% within a few hours. Sixteen percent wouldn't hack into a firewall even if they could.

"This may be stating the obvious," said Hamelin, "but poorly configured firewalls remain a significant risk for many organizations. It's not the technology that's at fault, but rather the configuration and change control processes that are neglected or missing altogether. Best practice suggests you should test and review your firewall configuration regularly, but many organizations fail to do so."

Validating the frustrating gap between compliance and security, seventy percent of the hackers interviewed don't feel that regulations introduced by governments worldwide to implement privacy, security and process controls has made any difference to their chances of hacking into a corporate network. Of the remaining 30%, 15% said compliance initiatives have made hacking more difficult and 15% believe they've made it easier.

"These results further validate the reality that there is little common ground between compliance and security, but as an industry we have the collective knowledge and the resources to change that," said Hamelin. "As the media constantly reminds us, while standards such as PCI-DSS provide a good baseline, organizations that assume achieving PCI compliance will solve their security woes are in for a rude awakening. With security and compliance budgets so deeply intertwined, it serves us as security professionals to make the two more synonymous. At the end of the day, the more accountable we are willing to be, the less we'll have to be."

With the Network Solutions breach being the latest in a series of widely reported breaches of PCI compliant companies, how big is the threat of a high-profile malicious hack? One important factor in determining that is to understand the scope of criminal activity.

Seventy percent of those sampled believe the number of malicious hackers - criminals motivated by economic gain-- is less then 25% of the of hacker community.

"This survey highlights the fact cyber security investments are only as effective as the people, processes and technology tasked with managing them," said Hamelin. "Just as a small subset of criminal hackers can taint the reputation of an entire community, a few good guys willing to be accountable for their internal processes and technology can preserve a company's reputation. With winter right around the corner, we have time to shift the dynamic from 86% who can hack into a network through its firewalls to 86% that can't."
Bookmark and Share
Home I Editor's Blog I News by Zone I News by Date I News by Category I Special Reports I Directory I Events I Advertise I Submit Your News I About Us I Guides
   © 2012
Netgains Logo