Heartland Payment Systems. Federal Reserve Bank of New York. Aetna. These are just a few of the organizations that were victims of major data breaches in 2009. While groups like the Privacy Rights Clearinghouse compile the final numbers to quantify the financial and personal impact for a year of blockbuster data breaches, security researchers and software vendors are looking back at what we can learn from 2009.
With 20-20 hindsight, enterprises can better secure their organizations from the next wave of attacks malicious hackers are undoubtedly already preparing for 2010 and beyond, whether from amateur hackers or criminal masterminds.
Positive and Negative Security Models
Perhaps ironically, the criminal mastermind behind 2009’s most well-recognized data breach was amateur hacker Albert Gonzalez, who gained access into the systems of credit-card processors, including Heartland Payment Services and retailers such as OfficeMax, Sports Authority, and TJX. Gonzalez used a drive-by hacking technique called wardriving.
Wardriving is an amateur hacking technique in which the hacker uses wireless access points to find vulnerable networks. Once Gonzalez connected to a vulnerable network, he used another simple technique called SQL injection to trick web applications into delivering private information. This scheme gave him further access to sensitive data. This strategy helped Gonzalez gain access to millions of credit- and debit-card numbers.
“Businesses need to ensure multiple security measures and security layers are in place to block hackers’ attempts to invade the network. The biggest lesson with this outage in 2009 is that an amateur hacker was able to access millions of credit- and debit-card numbers because basic security measures and technologies weren’t in place to prevent them,” said Citrix Systems Chief Security Strategist Kurt Roemer.
In this example, technologies like web application scanners or web application firewalls could have been utilized to prevent a security breach, Roemer said. A web application scanner…