Opinion: Four laws Congress needs to pass now to boost computer security
Laws need to require companies to take steps to prevent computer crimes, not react to them
Computerworld - Even though we have a new Congress, I doubt that much will change with regard to computer security. While a law related to identity theft will probably be passed in one form or another, I expect that it will be trivial and not deal with preventing the theft of individuals' personal information. Corporate lobbyists have proved themselves to be too adept at manipulating members of Congress so they don't pass laws requiring companies to be proactive, especially with regard to security measures.
Identity theft is a symptom of poor computer security. There are two underlying methods of identity theft: hacks of vendor computers, and client-side attacks. Vendor hacks are the result of poor security on the part of the vendor and often lead to the theft of thousands, or millions, of credit card numbers, at once. The laws passed in this regard basically state requirements that vendors have to follow once data is stolen. However, they do not lay out computer security requirements. The hope is that if vendors have to act if their security fails, they will try to better protect themselves. All you have to do is browse Computerworld.com to see how well that's working.
Congress, however, has taken no action to address client-side attacks targeting the end user. These include phishing, keystroke logging and virus attacks. The underlying enabler of these attacks are the bot networks that grow unchecked. Botnets are networks of PCs that have been compromised by a remote attacker through known vulnerabilities on the PCs. The attacker then has the compromised PCs do his bidding without the knowledge of the PCs' owners.
Bots send out billions of spam e-mails and their evil cousins, phishing messages. Just as important, bots are used for distributed denial-of service-attacks. DDoS attacks use thousands of computers to simultaneously send data packets to a victim's computer to overwhelm the computer and the supporting network infrastructure. The attackers then use the DDoS attacks to extort money from owners of various Web sites. For example, it's common for online gambling sites to be threatened prior to a major sporting event, where the attacker will say, "Unless you pay me $50,000, I will take you down for a day before the event." A successful attack could cost a good-sized gambling site more than $1 million.
Likewise, DDoS attacks have targeted critical elements of the Internet, such as the root DNS servers. Those attacks have crippled segments of the Internet for periods of time. It should be expected that similar attacks will occur in the future and will attempt to do even more damage. Frankly, I believe that if there is a significant Internet attack, it will involve bot networks.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts