A Kaulkin Ginsberg Publication
CRS
11/22/2009

Gartner II: Security through Obscurity Doesn’t Work Anymore

March 6, 2008
 
Digg!
What's this?

Google is the world's largest data aggregator, and so (excluding its users) it has the most to lose from a "great hack,” Gartner Research Vice President Whit Andrews told attendees at Gartner’s Compliance & Risk Management Summit 2008 in Chicago this week.

But Google is not the only target out there. Thousands of companies have implemented search engines for their enterprise data, while thousands of others enable employees to create blogs that describe corporate and personal matters. Millions of individuals use Google search on their desktops, and many of those individuals are indexing corporate as well as personal information, a tempting target for hackers.

Interactive Data - Who Are You Searching For?

Social Security Search. Bankruptcy Information. Directory Assistance (EDA). Real Estate Listings. Death Index.

Click here for more information...

While Google’s sheer size makes it a visible target, less visible enterprises should not assume that they are invisible, Andrews said. “Automated tools for search and analysis make security through obscurity less viable every day. And the same tools make it easier for a malicious actor to assess when a newly discovered server contains valuable data.

In short, this is not Google's problem. It is an environmental problem.”

With “search” such a business critical function and hackers propensity to go after big targets, Andrews expects to see a major denial of service attack against one of the major search providers by the end of this year. He also predicts that by the year 2010 criminals will demand to be paid not to damage search-related content.

Andrews recommends that a firm question its technology vendors whether its information access technology can combat denial-of-insight attempts. Any successful hacks will lead to negative publicity in addition to any immediate financial loss, resulting in the loss of customer accounts.

Therefore, firms should treat security as a strategic part of product selection, installation planning and ongoing execution, Andrews said. Additionally, firms shouldn’t implement an enterprise search engine before developing acceptable use and risk control policies and processes.

Among other ways to strengthen security at an enterprise that employs search technology, Andrews said, are:

  • Locking down the search logs and the administration rights.
  • Establishing a policy that employees may not have personal blogs that have anything to do with the company.
  • Assigning a corporate security or compliance officer.
  • “Hardening” search logs.
  • Informing users of the capabilities of the search engine and tell them how to hide information.
  • Using content monitoring and filtering tools.

 

Get Hired - jobsInsideARM.comHiring? Post a job - jobsInsideARM.com

Be the First To Comment

(Please read our comments policy first.)

From:
Show my identity with comment

Leave this field empty
Interested in more stories like this?
Tell us what topics you're interested in and we'll keep you posted. Enter your email address below.
B-Line, LLC
Lariat
Comtronic Systems
B-Line
  • DAKCS
  • Interior Concepts
  • URS
  • LoneStar
  • Interactive Data

Log In

Already registered? Log in here.





Forgot your password?

Register for FREE with insideARM

Create an account with insideARM and get access to our FREE newsletters and industry reports.








 

Check all | Uncheck all

Daily news and analysis
* Recommended *
Credit cards
Healthcare
Government/Municipal
Student loans
Mortgage
Auto finance
Collection agency operations
Collection technology
Debt purchasing
Recovery management
Hiring/Staffing
Job opportunities
Leave this field empty
 

You are already registered!

The email address you've entered is already in our database, meaning you've previously registered on insideARM.com.

All you have to do is log in using the form on the left.