Researcher says internal security breaches pose a bigger threat than hackers
August 3, 2009(PhysOrg.com) -- Periodic news accounts about computer hacking and deployment of worms and viruses strike fear in companies that now conduct much of their business online. But an Iowa State University information security researcher says their real fear should be corporate espionage.
"What our studies -- and many others by my colleagues in the field of information security -- have suggested is that internal computer fraud is a more significant issue than external hacking," said Qing Hu, a professor and chair of logistics, operations and management information systems at Iowa State. "External hacking gets headlines, but internal fraud -- employees actually altering data or stealing secrets and sending them to other companies -- is more prevalent than it is reported.
"The unfortunate thing is that companies don't want to report these types of things," he said. "It's only when you talk to individual companies that the manager will sometimes admit, 'Yes, we do have to discipline certain employees because they access commercial secrets that they weren't supposed to, and we had to fire some people because they sold some of our commercial secrets -- from product designs to marketing plans to pricing information -- to other companies.'"
Hu has spoken with such managers for research he's conducted on corporate information security management and user behavior toward protective technologies. Those studies -- which were part of a sponsored research program by the U.S. Department of Defense from 2005-07 -- were published within the last two years in information system journals. They took a different approach to addressing the security problem.
"When I look at a security issue, I do not focus on the technology," said Hu, who is a Microsoft Certified Systems Engineer and Solution Developer. "Information security technology is abundant -- hardware, software, etc. -- and organizations have invested millions of dollars purchasing that technology and installing it on their systems. But still, we hear horror stories about T.J. Maxx's system being broken into, 45 million credit card numbers being stolen, or something happening to this company or that company. So why do those things keep happening while we have invested so much money in terms of buying the security hardware and software?"
Hu contends it's because company employees aren't often educated well enough on information security policies and procedures. His research specifically examined how individual factors and an organization's culture affect its information security management effectiveness.
"The purpose of doing this research is first, to provide a better understanding of human behavior in organizations in the context of information security," Hu said. "Second, it's to provide some practical guidelines to businesses that say, 'OK, if you consider security to be a big issue, not only do you need to install the most sophisticated software and hardware, you also need to educate and set up those programs for employees -- and then enforce them.' So you have to have those processes in place to encourage good behavior and inhibit the potential bad behavior."
Hu is currently working with colleagues in the U.S., China and Finland on multiple research projects based on criminology theories and large-scale international surveys. The studies are designed to identify the individual factors -- such as moral beliefs and self-control -- that may affect a person's propensity to commit information security-related crimes.
"We want to understand why certain employees are more inclined to do bad things, while others are not," he said. "In the criminology research, there is a spectrum of theories and perspectives that explain why certain people are so inclined to commit crime, while others can inhibit that urge. So what I want to do in the immediate future is to explain that as it pertains to information security."
He hopes to have results from those surveys within the year. Hu also plans to collaborate with researchers from Iowa State's criminology and criminal justice program on future studies.
-
Managing computer fraud
May 23, 2008 |
not rated yet |
0
-
Cisco CEO to use 'holistic' security
Feb 17, 2006 |
not rated yet |
0
-
New research seeks to enhance quality and security of wireless telemedicine
Sep 17, 2007 |
not rated yet |
0
-
Wake-up call to business: Tighten up on information security
Jun 30, 2008 |
not rated yet |
0
-
Cyber attacks, losses on rise worldwide
Sep 13, 2005 |
not rated yet |
0
-
Fast photon control brings quantum photonic technologies closer
1 hour ago |
5 / 5 (2) |
0
-
Engineers build first sub-10-nm carbon nanotube transistor
Feb 01, 2012 |
4.9 / 5 (33) |
30
-
Something old, something new: Evolution and the structural divergence of duplicate genes
Jan 31, 2012 |
4.6 / 5 (7) |
1
-
The hidden nanoworld of ice crystals: Revealing the dynamic behavior of quasi-liquid layers
Jan 30, 2012 |
5 / 5 (5) |
1
-
Stock market network reveals investor clustering
Jan 27, 2012 |
3.9 / 5 (23) |
8
-
Quantum computer faster than regular computer?
4 hours ago
-
Flushing RAM in Mathematica
9 hours ago
-
Synergistic relations between computer science and technology.
Feb 06, 2012
-
how do iphone gloves work?
Feb 05, 2012
-
iPhone battery over time
Jan 30, 2012
-
Best alternate Tablet to an iPad for writing math or physics equations?
Jan 26, 2012
- More from Physics Forums - Computing & Technology
More news stories
Microsoft India retail site down after 'cyber attack'
Microsoft said Monday it was investigating an attack by hackers on its Indian retail website, reportedly carried out by a Chinese group called the "Evil Shadow Team."
5 hours ago |
not rated yet |
0
Chinese city seizes Apple iPads in name dispute
(AP) -- Authorities have seized Apple iPads from retailers in a city in northern China due to a dispute with a domestic company that says it owns the iPad name, an official said Monday. The Chinese company said it is asking ...
5 hours ago |
not rated yet |
0
AT&T customers surprised by 'unlimited data' limit
(AP) -- Mike Trang likes to use his iPhone 4 as a GPS device, helping him get around in his job. Now and then, his younger cousins get ahold of it, and play some YouTube videos and games.
7 hours ago |
5 / 5 (2) |
3
Independent group inspects Apple supplier
(AP) -- An independent group, the Fair Labor Association, has started auditing Apple Inc.'s Chinese supplier Foxconn after a request by Apple.
1 hour ago |
not rated yet |
0
Hacker claims porn site users compromised
A hacker claims to have compromised the personal information of more than 350,000 users after breaking into a disused website operated by pornography provider Brazzers.
6 hours ago |
5 / 5 (3) |
0
Slowing ocean current caused Earth to spin faster
(PhysOrg.com) -- Most people probably didn’t notice it, but back in 2009, the Earth spun around on its axis a tiny bit faster than usual, making for some slightly shorter days. It only happened for a ...
China's pollution related to E-cars may be more harmful than gasoline cars, researchers find
Electric cars have been heralded as environmentally friendly, but findings from University of Tennessee, Knoxville, researchers show that electric cars in China have an overall impact on pollution that could be more harmful ...
What we mean when we ask for the milk
New research into the different ways that English and Polish people use language in everyday family situations can help members of each community to understand each other better and avoid cultural misunderstandings.
Nerve sparing helps most prostate cancer patients to have same orgasms as before surgery
The vast majority of men who have a prostate cancer operation can retain their ability to orgasm if the surgery is carried out without removing the nerves that surround the prostate gland like a hammock, according to a study ...
Larger belly linked to memory problems in people with HIV
A larger waistline may be linked to an increased risk of decreased mental functioning in people infected with the AIDS virus HIV, according to research published in the February 14, 2012, print issue of Neurology, the me ...
Big fish reveal shelter secrets on reefcam
When it comes to choosing a place to hang out, big reef fish like coral trout, snappers and sweetlips have strong architectural preferences.