October 2010
Moving on
Today I found an interesting article on the symptoms that should make you thinking about ... leaving ... your job.
To be honest I don't even remember how I get to that site but apparently since I'm moving on in a slightly different career direction right now it was fun to read something like this.
I was tempted to extrapolate those symptoms in different plains and in search to see if I fit in the statistics and numbers, Margaret Heffernan shared :)
Enjoy!
Basic information security attack types
Purely technical
The attacker count on weaknesses in protocol implementation, application, OS, firmware etc..
Those attacks can be easily automated and if the vulnerability is well known pretty easy to defend of.
On the other hand the attack can come basically from any part of the world and is very hard to trace, because it passes occasionally through multiple systems covering the originating point
Physical attacks
The attacker aims to gain physical access to the targeted facility using weaknesses in one or more physical security controls. Of course those attacks are physically limited to the areas of the target premises etc. the attacker should be physically there.
Social engineering
The attacker rely on a major weakness in the meatware called trust. Those kind of attacks aim to fool someone from inside the organisation to trust external entity. The techniques employed most often include phone calls & e-mails.
Again since e-mails can be send basically from anywhere in the world and since phone calls can be chained easily and come from everywhere there is no geographical limitations for the attacker.
Those three basic types of attacks could be combined in order to achieve the ultimate goal - access to the targeted resources.
Two career options in IS - is it possible to blend them?
No matter if you want to be the best technical guru or you dream of becoming the greatest IS manager the information what is going on the other side will always keep you well balanced.
This is the main idea put together in the Anton Chuvakin blog post.
For a year or two I thought it's possible to keep going on both tracks, but then I saw that if you want to be really good you have to choose and keep going with your choice.
Enjoy!
Social networks, data mining and background checks :)
Few days ago I had several conversations with different people on the same topic - social networks and the result of growing exhibitionism trends out there.
Hopefully that article could bring some light
on how powerful sources a social network can be.
Enjoy

