Skip the navigation
Opinion

Opinion: Understanding your adversary

Our columnist suggests his detractors take 'The Hillary Test'

By Ira Winkler
June 1, 2006 12:00 PM ET

Computerworld - The most fun aspect of writing my Computerworld.com column is reading the hate mail.  It gives me a look inside the minds of people who think differently. Occasionally I learn why I was off-base about something, or I get information that helps me build out my understanding of a topic. More frequently, I see how people think, or how they don’tthink.

I recently delivered a column  on the current administration's abuse of the NSA for domestic-spying purposes. Unfortunately, most of my detractors never made an attempt to address the underlying facts, or to understand the argument being presented. The majority of those e-mails began with statements along the lines of "you're an idiot!" and went on to make assertions about my politics based on what they believed to have read in the column. (There were a few who claimed a minor typo compromised the entire legitimacy of the article, but anyone with much Usenet or mailing-list experience tends to dismiss the deductive abilities of that sort of correspondent.) [Typo was mine, Ira; sorry about that. I did enjoy reading those e-mails, though. -- Angela G., Ira's editor.] 

Correspondents who can't frame their criticisms coherently are amusing -- until I imagine them out in the field managing IT security, and then I start to worry. You'll never be a good security manager unless you understand why your adversaries think the way they do.  You don’t have to agree with them, but you need to know the logic underlying their actions.

For example, when I investigate a computer intrusion or an espionage attack, I must figure out as much as I can about the assailant's motivation and skills.  Is this a script kiddie who just wants the "prestige" of breaking into a system?  Or is the attempt part of an espionage operation by a foreign intelligence agency?  If the criminal party is an insider, are they malicious or are they greedy -- do they want to wreak havoc, or do they want money?

Why must I understand my adversary?  I need to guess the resources they might put into their crimes.  I need to figure out if they are sophisticated and might be going for valuable information, or they are just randomly fishing around.  I need to know if I should check whether they might have put time bombs in the system, or if they got what they were looking for and left.  I need to determine if they might be if they might have put backdoors in the system, or if they might have insiders supporting the efforts.



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Privacy White Papers
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
Streamline Compliance and Increase ROI
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
X-Ray of the PCI Process-4 Proactive Steps
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
All Privacy White Papers
Privacy Webcasts
A Road Map for Best Practice Social Media Acceptable Use Policy
Organizations around the world are racing to leverage the power of social media for business. Sites like Facebook are used for marketing, human...
Data Protection and Disaster Recovery with iSCSI and VMware
Get this on demand webcast now
Optimizing Networks for the Cloud
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
All Privacy Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs