Who Perpetrates Network Security Attacks?

An exploration of who perpetrates network security attacks and what are their motivations.

I suspect that there is no simple answer to who perpetrates network security attacks. But, the perpetrators can be categorised into two main groups:

Crackers

When crackers are mentioned most people think of spotty teenagers sitting in their bedrooms. I doubt that is a realistic view, after all yesterday’s teenage hacker is tomorrows adult hacker.

Crackers vary in sophistication from the so called ’script kiddies’ who are, perhaps the least technically sophisticated (though not necessarily the least damaging) to uber cognisant and experienced crackers. They do have one thing in common. They are trying to crack your network. They sit down and systematicaly attempt to break your network. This means that you must sit down and systematicaly ensure that they don’t crack your network. It’s kinda like a burglar. If you make your house nice and secure then the burglar is going to find somewhere easier to ply their trade.

The one good thing about your typical cracker is that at least they exist outside of your network. This gives you a great advantage. You construct the boundary that the cracker must penetrate in order to gain access to your network. So, at least you have a defendable border where you can deploy a range of tools to defend yourself.

Your own Users

Perhaps the most underestimated group of attackers is your own users. They may not have the level of sophistication of your average cracker, but they do have ONE big advantage. They wander into your office every day straight past all of your security defenses. They are plugged into the very heart of your network, behind your carefully constructed defenses.

For the vast majority of the time, your users are pretty benign. Users pose their most serious risk when combined with a cleverly worded trojan email. Some trojan emails are particularly clever in their psychology. We received one ourselves about a month ago purporting to be from administrator@openxtra.co.uk telling us that we needed to run the included attachment in order to cure a security problem on our machines. It made me look twice and I AM the administrator! In larger organisations where users are disconnected from their IT personel, some users may be tempted to do exactly what the email suggests.

Whilst your users are benign most of the time, they do sometimes perpetrate attacks completely by accident. Many companies grow in an ad-hoc manner, adding systems as and when necessary. Consequently, some things that really are essential are left undone. I recently saw a classical example of a system ripe to be attacked by a careless user. The router, through which all Internet traffic flowed, was hanging down against a wall with only a power cable supporting it. Of course, the router was just in an open piece of the office, where anybody could brush past it at any time. Another classic is placing servers under somebody’s desk. A sure fire recipe for some unplanned downtime and possible data loss.

Why do people perform Network Security Attacks

There are as many reasons for performing network security attacks as there are network security attacks. But, there are a number of common themes, in no particular order.

Related Articles & Links

Network Security Attacks - An Introduction

What Types of Network Security Attacks are Perpetrated?


About the Author

Jack Hughes Jack Hughes possesses extensive experience in the design and implementation of software projects, particularly specialising in network management and communications. In 2003 he co-founded OPENXTRA together with Denis Laverty using his skills as the technical and programming expert within the company as its Chief Technical Officer.