Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

DuPont Data Theft Shows Insider Risks

Scientist downloaded thousands of documents without being detected

February 19, 2007 12:00 PM ET

Computerworld - Gary Min worked as a scientist at DuPont for 10 years, focusing on research involving a type of high-performance film. He also covertly used DuPont’s computer systems to steal trade secrets valued at more than $400 million shortly before joining a rival company.

Min’s case, the details of which were unsealed last week by the U.S. attorney’s office in Delaware, is the latest — and perhaps most extreme — example of the dangers posed to corporate data by rogue insiders.

According to the court records, Min pleaded guilty in November to stealing proprietary data from DuPont by illegally downloading or accessing thousands of documents stored in an electronic library. Min, who also uses the first name Yonggang, is scheduled to be sentenced March 29 and faces a maximum of 10 years in prison plus a fine of up to $250,000.

What happened at DuPont vividly shows how trusted insiders can exploit IT weaknesses, as well as the challenges that companies face in stopping people from misusing systems, said Matt Kesner, chief technology officer at law firm Fenwick & West LLP in Mountain View, Calif.

User-by-User Security

“The old security model looked at the castle and ways to protect it with perimeter defenses,” Kesner said, noting that it made “intuitive sense” to many IT and security managers to implement firewalls, intrusion detection systems and other defenses aimed at preventing outsiders from breaking in. But that model is inadequate for dealing with insider threats, Kesner said.

“Frankly, we all have to actively stop thinking of insider vs. outsider” and focus on improving access controls for all users, he said. “It means looking at each and every person and machine as an island and deciding what rights and access each person and machine needs or doesn’t need.”

According to the information released last week, Min downloaded about 22,000 document abstracts from DuPont’s Electronic Data Library (EDL) server and accessed another 16,700 full-text PDF files. The various documents covered most of the company’s major products and technologies, including some that were still in the research and development stage.

The illegal activity occurred during a five-month period just prior to Min’s departure from DuPont in December 2005, the U.S. attorney’s office said. When the downloading began that August, Min was in active job discussions with Victrex PLC, a company based in Thornton Cleveleys, England, that he signed on with in October 2005 but didn’t join until the following January.

Although Min downloaded or accessed about 15 times more documents than the next-heaviest user of the



Jump to comments

Matt Kesner

Additional Resources

Microsoft
Here are some of the key reasons why you would want to run Unified Access Gateway with DirectAccess.
Microsoft
Review how one energy firm tightened protection and simplified IT work using business-ready security solutions.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

What People Are Saying

White Papers & Webcasts

Death to PST Files
Download Now  

Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".

eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!  

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...


IT Jobs