YOUR BUSINESS AUTHORITY

Springfield, MO

Log in Subscribe

Security needed to keep out computer hackers

Posted online

Corporate computers are under attack by cyber viruses and worms. New threats emerge daily, according to Symantec Corporation's annual Internet Security Threat Report. The Feb. 3 report, based on information obtained from 400 companies in 30 countries, showed that a company averages 30 attacks per week.

Many attacks result from computer-generated "sniffers," programs constantly running to find holes, said Ron Green, technology coordinator at the Southwest Missouri State University Computer Institute. Once a hole is found, the program alerts the hacker about the vulnerability. Such a program can be "working night and day to crack passwords," Green said.

Recognizing the growing need for securing systems, the SMSU Computer Institute has added CompTIA's vendor-neutral Security+ certification program. The program begins April 1. In May, the institute is adding a Microsoft security design class Windows: Designing Security for 2000.

"We're excited. We're a little ahead of the curve," said Green. Calling CompTIA an industry standard for certification on hardware and software, Green said the course was designed for information technology professionals to better enable them to determine how vulnerable their system is to attack and to learn how to protect their network.

While SMSU's Computer Institute educates businesses' technical staff about Internet security, outside input is also available from companies that believe an ounce of prevention has real meaning when dealing with protecting systems and data. Tritel Communications Inc., Networks Inc., and Layer3 Inc. are three area companies that offer such expertise.

Layer3 Inc. is mainly focused on "Internet security, which involves protecting networks from hackers, viruses and worms. This is done by installing security equipment such as firewalls, intrusion detection systems and content filtering along with secure network design and client/employee education," said Ryan McCoy, president.

Tritel Communi-cations Inc. is partnered with Sprint, CISCO Systems, Microsoft, IBM and Symantec, said Michael Zalewski, chief security officer for Tritel. "We do a lot of Internet security auditing, also standard firewalls, applications security and applications development."

Networks Inc. has a team of network and security professionals who work with businesses all over the Midwest, said Earl Johnson, partner.

All three companies can check or audit businesses for internal and external vulnerabilities.

But for basic protection, McCoy, Zalewski and Johnson advised businesses to have anti-virus software, firewall and intrusion detection systems.

It's not enough to simply install anti-virus software. It is a must to keep the anti-virus software updated, McCoy said. New viruses are constantly being created.

As a bare minimum, companies must install and monitor their firewalls to make them effective, said Zalewski, a certified Internet security specialist.

"(Companies should) inspect the logs, make adjustments to the firewall and implement an intrusion detection system which can proactively implement rules within the firewall to keep a hacker out."

Johnson defined a firewall as "a tool to prevent intruders from getting into your computer or network system. On an entry level, a single computer environment, a firewall may just be software. In a more corporate setting, a firewall typically consists of an appliance-type of device and a combination of hardware and software."

Zalewski described an intrusion detection system as "like a burglar alarm for a house while the firewall is like a padlock. When someone is able to break through the firewall, an intrusion detection system monitors the network and alerts when there is an intrusion."

Besides the obvious need to watch for the actions of unhappy employees or former employees, two of the many other vulnerable areas are passwords and downloading.

McCoy recommends passwords of six to eight characters including special characters. He suggested changing passwords "every 90 days and not permitting old ones to be reused."

On the same subject, Zalewski said don't write down passwords or tell anyone. "The majority of computer theft is internal, not external," Zalewski said.

Said McCoy: "Social engineering is one of the most popular ways people get information. Employees should be reminded constantly because it is very easy to do. For example, it is almost going home time and you receive a call asking for a password. The person identifies himself as a vendor needing access to fix your network. You are ready to leave so you give him what he wants. That night the hacker gets into your network and does his dirty work. Verify before giving passwords to anyone."

Downloading as a result of need-to-install messages' that appear when visiting an Internet site can be bad news. Zalewski warned that to click yes' to install might make your computer a server for "half the world."

Going about protecting your business and its data varies widely in cost. Much depends on how secure a business wants to be. Nothing however, is 100 percent effective.

The budget for Internet security is wide open, according to Johnson. He said it's in direct correlation to the size of a company's network and nature of the computers' use.

Said McCoy: "Fifteen (percent) to 20 percent of an information system's budget would be a conservative estimate for Internet security. However, a company needs to consider what a security incident would cost their company."

The time to consider putting safeguards in place is before something happens. Not only will that protect systems and sensitive data, but it also can keep costs down.

"It's easier to prevent a hack than to clean up after one. What might have taken us three days and $5,000 to prevent, might take three weeks and $30,000 to clean up," Zalewski said.

Comments

No comments on this story |
Please log in to add your comment
Editors' Pick
Fall 2026 Architects & Engineers Project Report

This installment of Springfield Business Journal’s Architects & Engineers Project Report showcases 26 endeavors by area design and engineering professionals.

Most Read
Update cookies preferences