• No results found

Physical Security to mitigate Social Engineering Risks

N/A
N/A
Protected

Academic year: 2021

Share "Physical Security to mitigate Social Engineering Risks"

Copied!
25
0
0

Loading.... (view fulltext now)

Full text

(1)

sonAl le n  LLP iftonLarsonAl ©2013  CliftonLar s ©2013  Cl

Physical Security to mitigate 

Social Engineering Risks

cliftonlarsonallen.com

(2)

sonAl

Agenda

©2013  CliftonLar s

Agenda

• Background and statistics of physical security • Address social engineering risks associated with  deficiencies in physical security  • Explain attacker motivations • Identify sound physical security measures to protect  critical assets  • Summarize key areas of control your organization  should have in place to improve the security posture

(3)

sonAl

Physical Security‐ It’s kind of a big deal

©2013  CliftonLar s

Physical Security It s kind of a big deal...

• The worldwide market for physical security was  valued at $48 billion in 2012 and is projected to  reach the market size of $125 billion by 20191. 1 http://www.transparencymarketresearch.com/physical‐security‐market.html

(4)

sonAl

And the winners are

©2013  CliftonLar s

And the winners are...

• Video Surveillance was the largest market and held  about 72% share in 2012 with a forecast to continue  that rapid growth2 • Biometrics held the largest market and held about  38% share in 20123

Trivia time...

What industry is the largest end‐user of physical  security? 

(5)

sonAl

Identify what needs to be protected

©2013  CliftonLar s

Identify what needs to be protected

People

People

Information

Information

E

i

t

Equipment 

F iliti

Facilities

(6)

sonAl

Defense in Depth

©2013  CliftonLar s

Defense in Depth

• The concept of protecting a computer network with  a series of defensive mechanisms such that if one  mechanism fails, another will already be in place to  th t tt k thwart an attack.

• Not enough to just secure your network

(7)

sonAl

©2013

 CliftonLar

s

Social Engineering Risks

Social Engineering Risks

(8)

sonAl

Social Engineering

©2013  CliftonLar s

Social Engineering 

• Hacking the human – Simply put, Social Engineering is the exploitation of human  nature. • Highest risk for these attacks? New employees [60%] – New employees [60%] – Contractors [44%]

(9)

sonAl

Several different attack vectors

©2013  CliftonLar s

Several different attack vectors

Online Telephone Waste Management Waste Management Personal approaches Reverse social  engineering

(10)

sonAl

Recon

Google it

©2013  CliftonLar s

Recon... Google it

• The information gathering process is critical.  The  internet can provide a host of information essential  to performing a successful social engineering attack • Google images  – Facility access, entrances T f t l d – Type of access control used – Employee information

• Information is a dangerous weapon Adds legitimacy • Information is a dangerous weapon.  Adds legitimacy 

(11)

sonAl

Tailgating

©2013  CliftonLar s

Tailgating

• Gaining access to a physical access facility by means  of coercion or manipulation or simple entry • Total bypass of physical security • Employees and vendors avoid confrontation • Attributed to deficient or lack of access restriction,  lack of security awareness “Cigarettes are a social engineer’s  best friend.”

(12)

sonAl

Sh

ld

S fi

©2013  CliftonLar s • Direct observation

Shoulder Surfing

• Effective in public areas  • Access to confidential information • Attributed to deficient privacy features, improperly  restricted areas 

(13)

sonAl

Dumpster Diving

©2013  CliftonLar s

Dumpster Diving

• Looking for information discarded by company  employees • Typically done after hours • Reconnaissance has likely been  done prior to attack • Attributed to lack of access restrictions, deficient  disposal procedures “One man’s trash is a social engineer’s treasure.”

(14)

sonAl

Motives

©2013  CliftonLar s

Motives

• Other motivators include knowledge, curiosity, ego, 

(15)

sonAl le n ftonLarsonAl ©2013  CliftonLar s ©2013  Cli f

Defensive measures to 

prevent Social Engineering 

attacks

(16)

sonAl

Types of Physical Security

©2013  CliftonLar s

Types of Physical Security

• Intrusion Detection/Prevention – Alarms, Video Surveillance • Access Control – Locks, Access control, Visitor control 

(17)

sonAl

Video Surveillance

©2013  CliftonLar s

Video Surveillance

• Video Surveillance is one of the oldest physical  security measures available – Now running on same IP network as other apps  b l f d – Must be securely configured  – Real time monitoring 

Unattended cameras simply aid in forensics – Unattended cameras simply aid in forensics 

• Placement is key

– All entrances work areas inside and outside of data – All entrances, work areas, inside and outside of data 

(18)

sonAl

Alarms

©2013  CliftonLar s

Alarms

• Perimeter and Internal – Various sensors can be implemented – Police response – Time of day restrictions can be enforced – Alarm codes should be unique for each employee Access is restricted using ACL

(19)

sonAl

Access Control it’s not just an IT problem

©2013  CliftonLar s

Access Control, it s not just an IT problem

• Relationship with facility management • Access review should occur regularly • Time of day restrictions • Layered security • Discuss options with vendorp

(20)

sonAl

Radio Frequency ID Cloning (RFID)

©2013  CliftonLar s

Radio Frequency ID Cloning (RFID)

• 3 levels of frequency – Low (LF) cloned within 3 ft – High (HF) cloned within 3‐10 ft – Ultra‐High (UHF) cloned within 30 ft • Most access control utilizes passive low frequency  RFID technology RFID technology • Discuss options with vendor

(21)

sonAl

Locks

©2013  CliftonLar s

Locks

• Virtually any key lock can be picked • If you MUST have key locks, implement   additional controls • Inventory of keys needs to be maintained • Electronic locks are best • Access codes should be unique for each employee • Access is centrally managedAccess is centrally managed

(22)

sonAl

Visitor Control

©2013  CliftonLar s

Visitor Control

• Guards – Human eyes are often better • Visitors announced and escorted  • Sign visitor log • Wear visitor badge (preferably automated access  control) • Implement compensating controls 

(23)

sonAl

Controlling Paper

©2013  CliftonLar s

Controlling Paper

• Locked shred bins • Vendor picks up and shreds onsite • Certificate of destruction is provided • Clean desk policy • Random walkthrough for compliance g p • Employee awareness

(24)

sonAl

Summary

©2013  CliftonLar s

Summary

• Layered security is best • Security is a culture • Validate your security • Security awareness is key

(25)

sonAl le n ftonLarsonAl P t St ©2013  CliftonLar s ©2013  Cli f Pete Storm Senior Associate, Information Security [email protected] 612‐397‐3070 612‐397‐3070 Laura Faulkner

Manager, Information Security Manager, Information Security [email protected] 267‐419‐1165

References

Related documents

While European countries have different standards for growing hemp, the overall standard is high, which often leads to a more quality product.. As the number of hemp farms grows

In this thesis first HOG based features are extracted from handwritten digits after than 10- class PSVM Classifier is used. Many handwritten digit classification

A signifi- cant decrease in cooling efficiency should be taken into consideration when designing spray cooling with emulsions and also when water spray cooling systems need to be

There were no significant differences between the sexes in the presence of stress ( Figure 3F ). In sum, our data suggest that non-stressed females have significantly more

Adapted to the specific requirements of the Airbus A320 family, the ED48 FDIMU combines mandatory flight data acquisition and high performance monitoring capabilities

 

Citation types The number of articles across all journals in the ISI-SSCI that cite the article until the end of December 2009, according to one of the following types of citation:

or more solutions that were available for customers to use by October 1, 2014 and that provide at least the following core predictive analytics functional components, tools,