Re:: CyberCrime Fighting FutureThought on IWS-Netspionage ...

Within the realm of IO, there is no safe haven and territorial boundaries become irrelevant as IO can be conducted at any time against any sector (public or private).
All other “cyber” activity (cybercrime, cyberterrorism, cyberwar, netspionage, hacktivism, etc.) is a subset of IO.

Note:: MnFuturists / FutureThought …Briefing at 13-Mar-2004 Investment SIG ... 
http://www.google.com/search?q=Netspionage+%22Case+Study%22+2004

 <-ClickToPAUSE (If using high bandwidth connections)
http://www.adaptiveavenue.com/performer.asp?rendition=www.google.com?
keywords=Netspionage "Case Study" 2004 <-Adapt Keyword search string to related areas

Applying Anticipatory Science Methods (ASM)
... www.users.qwest.net/~nhueser/futuresocdev.html Monday, August 12, 2002 Home
MHTA-MnTech Tekne Awards @ ACCTTS-LLC © 2002 ... Modified Delphi with matrix analysis. www.acctts.com/showcase/Articles/ _AnticipatoryScienceMetho.html

____________________

Background Citations:

@
http://www.giac.org/practical/GSEC/John_Kiesler_GSEC.pdf

 

GIAC: Global Information Assurance Certification - GSEC - SANS ...
... Small-site Information Security on a (very loose) shoestring - a case study. ... 72,
--, March 31,
2004. ... 2544, John Kiesler, Netspionage, 72, 79, --, January 31, 2005. ...
www.giac.org/GSEC_2600.php

The study, thought to be the first of its kind, found that almost half of the institutions taking part considered that the security breaches, sometimes known as netspionage,
posed a significant threat to their survival.

Symantec Enterprise Solutions
... 1995-2004 Symantec Corporation. ... that almost half of the institutions taking part considered
that the security breaches, sometimes known as netspionage, posed a ...
enterprisesecurity.symantec.com/ content.cfm?articleid=676

Description :

This book begins by laying out a history of espionage that clearly shows that when a new technology or technique becomes available to the information gatherers in public and private sectors, they can quickly be adopted for Netspionage use. It then moves on to describe how the Internet

SECURITY Books >> INTERNET AND THE WEB Books
... in public and private sectors, they can quickly be adopted for Netspionage use
...
encryption XKMS SAML XACML WS-Security P3P J2EE web services: Case study .NET web ...
www.computer-books-4jp.co.uk/internet-the-web/ security-6.htm


Netspionage
Worldwide Testing & Security Services, Inc.
Thomas J. Owens PhD

How Netspionage threatens business, infrastructure, and personal security
in the 21st Century.  This mini-tutorial addresses the three classes of Information Warfare;
Class 1 Personal, Class 2 Corporate, and Class 3 Nation State.
Topic scope includes case studies from prior investigations in 3 Fortune 500 Companies
 where Dr. Owens was employed.

Trained as a Quality Engineer, Dr. Owens had the unique experience to see first hand the results of Information Warfare and Netspionage in the high tech computer and aerospace industries.
Dr. Owens will relate these experiences along with current and future threats
to escalating local, regional, and global disruptions.
__________________________________________

Cellular Phone News--Newsletter: March 12, 2003
... Group stating that one time porting fees, demands ... SBC Communication and Qwest
are also seeking ... Unprotected wireless use exposes companies and individuals to ...
www.cellularphonenews.com/newsletter/2003/082703.htm

The Csi/FBI survey of 2003 shows once again that there are significant levels
of hacking, system penetration, eavesdropping,
[ URL:
http://www.iwar.org.uk/cip/resources/senate/economy/cross.htm -
 77KB - 30 Jan 2003 ] 


sabotage, theft of proprietary information and insider abuse of companies' computer systems. Wireless looks like a very easy way to carry out many of these activities, given the ease of access and the low likelihood of detection.
Via:: 
http://www.google.com/search?q=Qwest+Wireless+Porting+Sabotage
<-(Facts or Fantasy in Qwest-Land?)

Computer Viruses
: The Disease, the Detection, and the Prescription for Protection

Subcommittee on Telecommunications and the Internet
November 6, 2003 :: 09:30 AM :: 2123 Rayburn House Office Building 

Mr. Richard D. Pethia
Director::
CERT Coordination Center Software Engineering Institute
Carnegie Mellon University :: Pittsburgh, PA, 15213


Information Assurance – the Achilles’
Heel of Joint Vision 2010?

SUBCOMMITTEE ON GOVERNMENT EFFICIENCY,
FINANCIAL MANAGEMENT AND INTERGOVERNMENTAL RELATIONS

By applying the 80/20 rule, organizations can likely prevent 80 percent of potential worm attacks to their infrastructure, by addressing just the top 20 percent of good security practices.

This is a very good first step. However, the growth of home broadband connections raises further concerns that a worm could spread rapidly to millions of Internet users and drastically impact the operation of our economy.
[PDF] Contents
File Format: PDF/Adobe Acrobat - View as HTML
Page 1. Contents GIS-1 GIS: SCIENCE, APPLICATIONS, COHERENCE ...
www.amproductions.com/pdfs/GISCATALOGUE.pdf
Via:: http://www.google.com/search?q=SIRT+Matrix+Meta+Security

GIS products, services, and solutions for business
Your best friend in the mapping business! Our mission is to provide
the very best in mapping services and data to our clients. For ...
Description: Site dedicated to the application of GIS in business. DSS provides one-stop shopping for GIS software,...
Category:
Computers > CAD and CAM > Mapping and GIS
http://www.dsslink.com/
- 7k - Cached - Similar pages

GIS.com--Your Internet Guide to GIS (Geographic Information ...
What Is GIS? How To Use GIS. How to Do GIS Analysis. Why Use GIS? GIS Touches our
Everyday Lives. Related Web Links. Links to Live Mapping Sites. Submit Your Site. ...
Description: Provides introductory overviews on many aspects of GIS. Find information about industries, curriculums...
Category:
Science > Social Sciences > ... > Geographic Information Systems
http://www.gis.com/

End:: Netspionage "M-O-M-Matrix" :&: Qwest Wireless Porting Sabotage (4306am)

Netspionage_M-O-M-Matrix_4306.doc


Relationship

 

Profile


Motive

Opportunity

(Means)


Methods

Frequency
[H-M-L]

Impacts
[H-M-L]

Effective

Safeguards

Proven
Practices

Mandated
Controls

 

 

 

 

 

 

 

 

 

 

Insiders:

(In-laws?)

Clueless
User

None

Access &
Authorization

Error &
Omissions

High

 

Low-Med

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Contractor

Varies

 

Weak
Controls

Exploits  Lax
Controls

Unknown

Med-High

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Disgruntled
Stakeholder

Get Even

Insider
Insights

Exploits  Lax
Controls

Low-Med

High

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Gamers
(MUDD)

Have Fun

After Hours
Diversions

Compromises
Controls

Low

Med-High

 

 

 

 

 

 

 

 

 

 

 

 

 

Outsiders:

(Outlaws?)

Script
Kiddie

Intellectual
Curiosity

Spare Time
Lax Parents

Freeware

High

Low-Med

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Hacktivist

Political
Causes

See
Below

Various

Unknown

Med-High

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Coder / Pro
(Core Wars)

Peer
Recognition

Lax Software
Quality

Discovers
Loopholes

Low

High

(Day Zero)

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Comp Intel  & Economic

Espionage

 

Economic
Gain

 

 

 

Medium

 

High

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

State-Sponsored
Netspionage

Economic
& Political
Gains

 

 

Unknown


(
See Survey)

 

High

 

 

 

 

 

 

 

 

 

 

 

 

 

© 2001-2004  by ACCTTS,  LLC.  All Rights Reserved Worldwide.

MS-IE Only Ref: Security Incident Response Program Development  [ACCTTS-SIRT Selection Support Benchmark]
 Whitepapers:
http://www.metasecuritygroup.com/ & Launch Glossary of Terms Search


 


Operational

Risk

Factors:

Type Digital
Disruption

Outage
Impacts?
[H-M-L]

 

Outage
Scope?

Time- Critical
Window?

 

Outage
Duration?

Protection

Policy

Pre-Reqs

Defined

SIRT

Roles

Key
Resp. &
Resources

Desired
Results

Metrics?

 

 

 

 

 

 

 

 

 

 

 

 

Anti-Social
Engineering

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Deletion

(Accidental)

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Denial of Service

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Destruction
(Intentional)

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Errors &
Omissions

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Unauthorized Access

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Unauthorized Disclosure

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Unauthorized
Duplication

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Unauthorized
Modification

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Network Abuse
or Misuse

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

© 2001-2004 by ACCTTS,  LLC.  All Rights Reserved Worldwide.


Gartner Group:  Information Systems Security Dimensions
 
 
Requirement
 
Definitions

(Via DISA: ISO/IEC 7498-2)

 
Safeguard Technique

 

 
Non-Interference
 
Ensure that control is exercised over the entry and use
of an enterprise’s electronic assets.

 

§         User ID / Password
§         Firewall
§         Password nondisclosure
§         UCC4A unauthorized-use banner
 
Authentication
 
Ensure that users and/or applications are uniquely identified
in order to gain access to information assets.

 

§         User ID / Password
§         Token
§         Biometric device

§         PKI protocols

§         Location

 
Authorization
 
Ensure that a correctly authenticated user can access only
those resources to which the owner has given them approval.

 

§         Access control list

§         Attribute certificates

 
Confidentiality
 
Ensure that only those people who have a need
to see information are able t see it.

 

§         Encryption
 
Integrity
 
Ensure that it can be identified if a transaction has changed
between the sender and the receiver.  [Correct, Complete & Timely]

 

§         Message Authentication Code (MAC) / hash

 

Gartner Group:  Information Systems Security Dimensions
 
 
Requirement
 
Definitions

(Via DISA: ISO/IEC 7498-2)

 
Safeguard Technique

 

 
Privacy
 
Ensure that information provided by employees, customers and others is protected such that it is used solely for the stated purposes of the enterprise, the person authorised such use and the enterprise is
in compliance with all local privacy regulations.

 

§         Policies and procedures
§         Encryption
§         Policy management tools

 

 
Nonrepudiation
 
Ensure that both the sender and receiver of information can unequivocally prove that the exchange occurred
between the two parties. 
(
Repudiation: Rejecting a transaction’s validity in a court of law.)
§         Digital Signature

§         Timestamp

 
Availability
 
Ensure that the enterprise has suitable recoverability and protection from system failures, natural disasters or malicious attacks.

 

§         Redundancy

§         Load balancing

§         Policies and procedures

§         Exercised Business continuity plan

§          Alternate processing site(s)

Source:
 
http://mdev.temple.edu/gartner/research/ras/98600/98601/98601.html

 

ACCTTS-SIRT-M_O_Matrix.doc

 


Eco-Futures & ELDER-Treks via LearnSD

 

FutureThought Global Brain TRUST … What-IF?

For more information:

http://www.acctts.com/i4ftl/index5.html



Intrinsic Motive Profiling (IMP) for Crisis Mgt. Preparedness (CMP)

:@: http://www.acctts.com/RecyclingSteps/

Netspionage_M-O-M-Matrix_4306.doc