Technology Sectors

Market Sectors

USB ploy by DHS exposes curiosity as security flaw

Jevans: employees are
attack vector

What would you do if you found a USB stick in your office parking lot on the way to your cubicle in the morning? Would you pick it up? Would you plug it into your computer?

Looking for some answers to those questions, the U.S. Department of Homeland Security ran a little experiment. It sprinkled computer discs and USB sticks — some labeled with a logo, some without — in the parking lots of government buildings and those of private contractors and waited to see what would happen.

It found that 60 percent of the people who picked up the media plugged them into their computers. For the media labeled with logos, the percentage was even higher — 90 percent.

"That tells a criminal how to infiltrate a government network," Dave Jevans, chairman of IronKey in Sunnyvale, CA, told Government Security News. "The last time I checked. Criminals can read."

"For one or two hundred dollars, I can pay a high school kid to sprinkle some infected USB drives in the parking lot of the Pentagon and other places and nine out of 10 times some guy is going to plug it in," he observed. "I don't have to worry about your firewall, your IDS [Intrusion Detection System], your IPS [Intrusion Protection System] or any of that stuff."

"You could have spent $50 million securing your network," he continued, "and I could penetrate it by spending $200."

The seeding a parking lot trick is a low rent tactic compared to what's being done by more sophisticated cyber bandits. "We've seen manufacturing plants compromised, where malware is being installed on drives before they leave the factory," said Jevans, whose company protects against credential stealing malware used by criminals, terrorists, and rogue nations that pose a threat to government data.

Without a doubt, the end user is one of the most vulnerable points in a security scheme, he maintained. "There are a great many ways to socially engineer users," he explained, but the free USB ploy seems to be a particularly effective one.  He recalled a bank conducting an experiment similar to the DHS one, with similar results.

"The results of experiments like this are something we should all be thinking about," he advised. "When people want to break into our networks, they're going to do it through our employees. They're not going to do it by crashing our firewalls or breaking our IPS's. They're going to do it by tricking our employees."

A full report on its security experiment is expected to be released later this year by the department, according to Bloomberg.

 

Upcoming Events

Event Details Dates of Event
SANS Austin 2013 May 19 - 24
DoD VA Healthcare Training Forum May 20 - 23
Transport and Logistics of Hazardous Material May 27 - 28
Southwest Microwave Seminar May 28 - 28
Border Management Southwest Summit May 29 - 31
Cyber Security Conference & Expo May 30 - 30
Mobile Device Security Summit 2013 May 30 - Jun 6
Security Analytics Summit 2013 May 30 - Jun 6
Cyber Security Conference & Expo May 30 - 30
Southwest Microwave Seminar May 30 - 30
SANS Malaysia @ MCMC 2013 Jun 3 - 8
2013 SIA Government Summit Jun 4 - 5
Southwest Microwave Seminar Jun 4 - 4
NCT: CBRNe Israel, 4 - 6 June 2013, Tel Aviv Jun 4 - 6
SEL Modern Solutions Power Systems Conference Jun 5 - 7
Mission Command Jun 10 - 12
Cyber Securty Brainstorm Jun 11 - 11
EDGE Summit 2013 Jun 11 - 11
IPv6 Summit 2013 Jun 14 - 16
SANSFIRE 2013 Jun 15 - 22
Oak Ridge National Laboratory's 2nd Biosurveillance Symposium Jun 17
Biodetection Technologies 2013 Jun 18 - 19
Southwest Microwave Seminar Jun 18 - 18
Cyber Defense and Network Security Summit Jun 24 - 26
Vanguard Security & Compliance 2013 Jun 24 - 27
SANS Canberra 2013 Jul 1 - 13
Border Management & Technologies Summit Jul 2 - 5
SANS Rocky Mountain 2013 Jul 15 - 20
SANS Mumbai 2013 Jul 22 - 27
SANS San Francisco 2013 Jul 29 - Aug 3
SANS Boston 2013 Aug 5 - 10
Cyber Security for Government Aug 12 - 14
SANS Thailand 2013 Aug 19 - 31
SANS Virginia Beach 2013 Aug 19 - 30
Maritime Security 2013 West Aug 19 - 21
930gov: Strategic Buying at Year-End Showcase Aug 21 - 21