R E L A T E D   C O N T E N T
ADVERTISEMENT

Poor evidence taking lets off hackers

Firms failing to deploy proper audit trails, warns security study

Robert Jaques, vnunet.com 04 May 2004
ADVERTISEMENT

Few companies have the proper audit trails in place to get convictions against hackers, according to security firm NTA Monitor.

The company claims that its research shows firms failing to maintain log files adequately - and in some cases not bothering to switch the logs on at all.

Roy Hills, technical director at NTA Monitors, said companies do not turn on their logs because traffic gets monitored elsewhere, and because it uses up too much disk space.

"Other companies do log, but don't keep the records long enough," he added.

"I've seen several huge corporations where the log files are overwritten every 30 minutes. If they were attacked, there would be no record of what had happened.

"Then there are the people who are logging but not getting it right - like storing the information on public folders that hackers can access and easily cover their tracks."

Companies also forget time synchronisation, said Hills. A serious incident is likely to involve several different systems, but companies cannot piece together what has happened if they are unable to track from one log to another.

The Home Office is to review the existing Computer Misuse Act to see if it still provides enough protection against hackers and other problems.

But Hills said: "Most companies won't be able to supply the evidence needed to secure convictions, meaning criminals will get off scot-free despite any change in law."

See also:

All Party Internet GroupReport recommends stiffer penalties and for DoS attacks to be made a criminal offence  30 Jun 2004
Security breaches cause 'significant' number of legal practices to lose clients  07 Jun 2004
Computer Misuse Act needs updating 'to address the network world', experts tell inquiry  05 May 2004
All-party group holds public inquiry into 'ineffective and inadequate' Computer Misuse Act  28 Apr 2004
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004
Met PoliceShared intelligence on attacks will help fight cyber-crime, says Met  31 Mar 2004

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
C# Web Developer, Finance, London Financial Services Required: C#, ASP.NET, AJAX Fantastic opportunity not to be missed!! This is a great opportunity to work on a unique objectives that no other company is doing working ... more >
| JAM Recruitment
Senior Hardware Engineer Scotland/Edinburgh Communication Systems Permanent Position 40-45K+Benefits A leading organisation involved with the design and development of data acquisition systems and synthesis boards for a range of radar, signal intelligence and software radio ... more >
| JAM Recruitment
FPGA Engineer Defence/Safety Critical Buckinghamshire Permanent Position 45K+Benefits A leading UK defence organisation requires an experienced digital design engineer to strengthen its existing development team due to a number of long-term projects that have recently ... more >
| JAM Recruitment
DSP Engineer 3 Months Contract Hertfordshire £Excellent Rates£ This position requires you to have experience of measurement algorithms development for the generation and analysis of digital wireless communication standards including GSM, EDGE, UMTS, WLAN and ... more >
More job opportunities