Information protection policy

Автор работы: Пользователь скрыл имя, 28 Ноября 2012 в 04:31, реферат

Описание работы

Information protection policy is a document which provides guidelines to users on the processing, storage and transmission of sensitive information. Main goal is to ensure information is appropriately protected from modification or disclosure. It may be appropriate to have new employees sign policy as part of their initial orientation. It should define sensitivity levels of information.
Content
Should define who can have access to sensitive information.
Should define how sensitive information is to be stored and transmitted (encrypted, archive files, uuencoded, etc).

Файлы: 1 файл

information.docx

— 138.30 Кб (Скачать файл)

 

Agents and the process of collection

Economic or industrial espionage commonly occurs in one of two ways. Firstly, a dissatisfied employee appropriates information to advance their own interests or to damage the company or, secondly, a competitor or foreign government seeks information to advance its own technological or financial interest[8] 'Moles' or trusted insiders are generally considered the best sources for economic or industrial espionage.Historically known as a 'patsy,' an insider can be induced, willingly or under duress to provide information. A 'Patsy' may be initially asked to hand over inconsequential information and once compromised by committing a crime, bribed into handing over material which is more sensitive. Individuals may leave one company to take up employment with another and take sensitive information with them.Such apparent behavior has been the focus of numerous industrial espionage cases that have resulted in legal battles. Some countries hire individuals to do spying rather than make use of their own intelligence agencies. Academics, business delegates and students are often thought to be utilized by governments in gathering information.Some countries, such as Japan, have been reported to expect students be debriefed on returning home. A spy may follow a guided tour of a factory then get 'lost'. A spy could be an engineer, a maintenance man, a cleaner, a insurance salesman or an inspector - basically anyone who has legitimate access to the premises.[

A spy may break into the premises to steal data. They may search through waste paper and refuse, known as "dumpster diving". Information may be compromised via unsolicited requests for information, marketing surveys or use of technical support, research or software facilities. Outsourced industrial producers may ask for information outside of the agreed-upon contract.

Computers have facilitated the process of collecting information, due to the ease of access to large amounts of information, through physical contact or via the internet.

 

Use of computers and the Internet

Personal computers

Computers have become key in exercising industrial espionage due to the enormous amount of information they contain and its ease of being copied and transmitted. The use of computers for espionage increased rapidly in the 1990s. Information has been commonly stolen by being copied from unattended computers in offices, those gaining unsupervised access doing so through subsidiary jobs, such as cleaners or repairmen. Laptops were, and still are, a prime target, with those traveling abroad on business being warned not to leave them for any period of time. Perpetrators of espionage have been known to find many ways of conning unsuspecting individuals into parting, often only temporarily, from their possessions, enabling others to access and steal information. A 'bag-op' refers to the use of hotel staff to access data, such as through laptops, in hotel rooms. Information may be stolen in transit, in taxis, at airport baggage counters, baggage carousels, on trains and so on.

 

The Internet

The rise of the internet and computer networks has expanded the range and detail of information available and the ease of access for the purpose of industrial espionage. Worldwide, around 50,000 companies a day are thought to come under cyberattack with the rate estimated as doubling each year.This type of operation is generally identified as state backed or sponsored, because the 'access to personal, financial or analytic resources' identified exceed that which could be accessed by cybercriminals or individual hackers. Sensitive military or defense engineering or other industrial information may not have immediate monetary value to criminals, compared with, say, bank details. Analysis of cyberattacks suggests deep knowledge of networks, with targeted attacks, obtained by numerous individuals operating in a sustained organized way.

 

Opportunities for sabotage

The rising use of the internet has also extended opportunities for industrial espionage with the aim of sabotage. In the early 2000s, it was noticed that energy companies were increasingly coming under attack from hackers. Energy power systems, doing jobs like monitoring power grids or water flow, once isolated from the other computer networks, were now being connected to the internet, leaving them more vulnerable, having historically few built-in security features.[20] The use of these methods of industrial espionage have increasingly became a concern for governments, due to potential attacks by terrorist groups or hostile foreign governments.

Malware

One of the means of perpetrators conducting industrial espionage is by exploiting vulnerabilities in computer software. Malware and spyware as 'a tool for industrial espionage,' in 'transmitting digital copies of trade secrets, customer plans, future plans and contacts'. Newer forms of malware include devices which surreptitiously switch on mobile phones camera and recording devices. In attempts to tackle such attacks on their intellectual property, companies are increasingly keeping important information off network, leaving an 'air gap,' with some companies building '"Faraday cages"' to shield from electromagnetic or cellphone transmissions.

 

Distributed denial of service (DDoS) attack

The distributed denial of service (DDoS) attack uses compromised computer systems to orchestrate a flood of requests on the target system, causing it to shut down and deny service to other users.It could potentially be used for economic or industrial espionage with the purpose of sabotage. This method was allegedly utilized by Russian secret services, over a period of two weeks on a cyberattack on Estonia in May 2007, in response to the removal of a Soviet era war memorial.

 

History

Origins of industrial espionage

Economic and industrial espionage has a long history. The work of Father Francois Xavier d'Entrecolles in Jingdezhen, China to reveal to Europe the manufacturing methods of Chinese porcelain in 1712 is sometimes considered an early case of industrial espionage. Historical accounts have been written of industrial espionage between Britain and France. Attributed to Britain's emergence as an 'industrial creditor,' the second decade of the 18th century saw the emergence of a large-scale state-sponsored effort to surreptitiously take British industrial technology to France.[25] Witnesses confirmed both the inveigling of tradespersons abroad and the placing of apprentices in England.[26] Protests by those such as iron workers in Sheffield and steel workers in Newcastle,[clarification needed] about skilled industrial workers being enticed abroad, led to the first English legislation aimed at preventing this method of economic and industrial espionage.

 

During the Cold War

With Western restrictions on the export of items thought likely to increase military capabilities to the USSR, Soviet industrial espionage was a well known adjunct to other spying activities up until the 1980s.

 

"Operation Brunnhilde"

Some of these activities were directed via the East German Stasi (Ministry for State Security). One such operation, known as "Operation Brunnhilde" operated from the mid-1950s until early 1966 and made use of spies from many Communist Bloc countries. Through at least 20 forays, many western European industrial secrets were compromised.One member of the "Brunnhilde" ring was a Swiss chemical engineer called Dr Jean Paul Soupert, also known as 'Air Bubble,' living in Brussels. He was described by Peter Wright in Spycatcher as having been 'doubled' by the Belgian Sûreté de l'État.He revealed information about industrial espionage conducted by the ring, including the fact that Russian agents had obtained details of Concorde's advanced electronics system. He testified against two Kodak employees, living and working in Britain, during a trial in which they were accused of passing information on industrial processes to him, though they were eventually acquitted.

 

Soviet spetsinformatsiya system

A secret report from the Military Industrial Commission (VPK), from 1979–80, detailed how spetsinformatsiya could be utilised in twelve different military industrial areas. Writing in the Bulletin of the Atomic Scientists, Philip Hanson detailed a spetsinformatsiya system in which 12 industrial branch ministries formulated requests for information to aid technological development in their military programs. Acquisition plans were described as operating on 2 year and 5 year cycles with about 3000 tasks under way each year. Efforts were aimed at civilian as well as military industrial targets, such as in the petrochemical industries. Some information was garnered so as to compare levels of competitor to Soviet technological advancement. Much unclassified information was also gathered, blurring the boundary with 'competitive intelligence'.

 

The Soviet military was recognised as making much better use of acquired information, compared to civilian industry, where their record in replicating and developing industrial technology was poor.

 

The legacy of Cold War espionage

Following the demise of the Soviet Union and the end of the 'Cold War,' commentators, including the US Congressional Intelligence Committee, noted a redirection amongst the espionage community from military to industrial targets, with Western and former communist countries making use of 'underemployed' spies and expanding programs directed at stealing such information. The legacy of 'Cold War' spying included not just the redirection of personnel but the use of spying apparatus such as computer databases, scanners for eavesdropping, spy satellites, bugs and wires.

 

Notable cases

France and the United States

In 1991 Air France was accused of helping its spy agency garner corporate secrets through installing microphones in its seats. Between 1987 and 1989, IBM and Texas Instruments were also thought to have been targeted by French spies with the intention of helping France's Groupe Bull.In 1993, US aerospace companies were also thought to have been targeted by French interests. During the early 1990s, France was described as one of the most aggressive pursuers of espionage to garner foreign industrial and technological secrets. France accused the U.S. of attempting to sabotage its high tech industrial base.The government of France has been alleged to have conducted ongoing industrial espionage against American aerodynamics and satellite companies.

 

Volkswagen

In 1993, car manufacturer Opel, the German division of General Motors, accused Volkswagen of industrial espionage after Opel's chief of production, Jose Ignacio Lopez, and seven other executives moved to Volkswagen. Volkswagen subsequently threatened to sue for defamation, resulting in a four-year legal battle. The case, which was finally settled in 1997, resulted in one of the largest settlements in the history of industrial espionage, with Volkswagen agreeing to pay General Motors $100 million and to buy at least $1 billion of car parts from the company over 7 years, although it did not explicitly apologize for Lopez's behavior.

 

Hilton and Starwood

In April 2009 the US based hospitality company Starwood accused its rival Hilton of a "massive" case of industrial espionage. After being purchased by private equity group Blackstone, Hilton employed 10 managers and executives from Starwood. Under intense pressure to improve profits, Starwood accused Hilton of stealing corporate information relating to its luxury brand concepts, used in setting up its own Denizen hotels. Specifically, former head of its luxury brands group, Ron Klein, was accused of downloading "truckloads of documents" from a laptop to his personal email account.

 

GhostNet

GhostNet was a 'vast surveillance system' reported by Canadian researchers based at the University of Toronto in March 2009. Using targeted emails it compromised thousands of computers in governmental organisations, enabling attackers to scan for information and transfer this back to a 'digital storage facility in China'.

 

Google and Operation Aurora

On January 13, 2010, Google Inc. announced that operators, from within China, had hacked into their Google China operation, stealing intellectual property and, in particular, accessing the email accounts of human rights activists. The attack was thought to have been part of a more widespread cyber attack on companies within China which has become known as Operation Aurora. Intruders were thought to have launched a zero-day attack, exploiting a weakness in the Microsoft Internet Explorer browser, the malware used being a modification of the trojan Hydraq.Concerned about the possibility of hackers taking advantage of this previously unknown weakness in Internet Explorer, the Government of Germany, then France, issued warnings not to use the browser.

 

There was speculation that 'insiders' had been involved in the attack, with some Google China employees being denied access to the company's internal networks after the company's announcement. In February 2010, computer experts from the U.S. National Security Agency claimed that the attacks on Google probably originated from two Chinese universities associated with expertise in computer science, Shanghai Jiao Tong University and the Shandong Lanxiang Vocational School, the latter having close links to the Chinese military.

 

Google claimed at least 20 other companies had also been targeted in the cyber attack, said by the London Times, to have been part of an 'ambitious and sophisticated attempt to steal secrets from unwitting corporate victims' including 'defence contractors, finance and technology companies'. Rather than being the work of individuals or organised criminals, the level of sophistication of the attack was thought to have been 'more typical of a nation state'. Some commentators speculated as to whether the attack was part of what is thought to be a concerted Chinese industrial espionage operation aimed at getting 'high-tech information to jump-start China’s economy'.Critics pointed to what was alleged to be a lax attitude to the intellectual property of foreign businesses in China, letting them operate but then seeking to copy or reverse engineer their technology for the benefit of Chinese 'national champions'.In Google's case, they may have (also) been concerned about the possible misappropriation of source code or other technology for the benefit of Chinese rival Baidu. In March 2010 Google subsequently decided to cease offering censored results in China, leading to the closing of its Chinese operation.

 

CyberSitter and 'Green Dam'

The US based firm CyberSitter announced in January 2010 that it was suing the Chinese government, and other US companies, for stealing its anti pornography software, with the accusation that it had been incorporated into China's Green Dam program, used by the state to censor Chinese[48] citizens' internet access. CyberSitter accused Green Dam creators as having copied around 3000 lines of code. They were described as having done 'a sloppy job of copying,' with some lines of the copied code continuing to direct people to the CyberSitter website. The attorney acting for CyberSitter maintained “I don't think I have ever seen such clear-cut stealing".

 

USA v. Lan Lee, et al

The United States charged two former NetLogic Inc. engineers, Lan Lee and Yuefei Ge, of committing economic espionage against TSMC and NetLogic, Inc. A jury acquitted the defendants of the charges with regard to TSMC and deadlocked on the charges with regard to NetLogic. In May 2010, a federal judge dismissed all the espionage charges against the two defendants. The judge ruled that the U.S. Government presented no evidence of espionage.

 

 

Dongxiao Yue and 'Chordiant Software, Inc'

In May 2010, the federal jury convicted Chordiant Software, Inc., a U.S. corporation, of stealing Dr. Dongxiao Yue's JRPC technologies and used them in a product called 'Chordiant Marketing Director'. Dr. Yue previously filed lawsuits against Symantec corporation for a similar theft.

 

Stuxnet Worm

Stuxnet is a computer worm which affected Iran's Bushehr nuclear power plant in September 2010. Designed to target weaknesses in Siemens electronic industrial systems, it is thought to be capable of seizing control of industrial plants and to be the first 'worm' created for this purpose.The complexity of its design and targeted purpose left Western computer experts suggesting it could only have been the product of a "nation state". (Some security experts suggested Israel;others suggest the United States; still others suggest a combined effort of the two. Mahmoud Liayi, from Iran's Ministry of Industries, is quoted as saying, "an electronic war has been launched against Iran". As well as targeting nuclear power stations, it is also capable of attacking systems which manage water supplies, oil rigs and other utilities.

According to the British Daily Telegraph a video played at the retirement party of the former Israel Defence Forces (IDF) chief of staff, Gabi Ashkenazi, claimed the worm as one of his "operational successes".

 

Operation Payback

Distributed Denial of Service (DDoS) attacks were utilised by a network of hackers, led by the self styled group 'Anonymous', in orchestrating what was termed Operation Payback, in December 2010.This was aimed at sabotaging the websites of corporations such as Mastercard, Visa and Paypal, who had stopped Wikileaks donors using their financial services, allegedly under pressure from the United States Government. Thousands of people participating in the attacks did so through downloading the readily available open source LOIC (Low Orbit Ion Cannon) DDoS tool, leading to some commentators to note that, rather than worrying whether their credit card numbers had been hacked, parents should be concerned as to whether their teenage child was an amateur 'hackitivist', possibly 'participating in a co-ordinated global attack on major financial institutions'. With Wikileaks founder Julian Assange in Wandsworth prison on charges of sexual assault, the hackers threatened to bring down United Kingdom Government websites, should he be extradited to face charges in Sweden. However, 'Security experts' derided the idea that 'Operation Payback' was in any way comparable to cyber warfare, claiming attacks of this kind were very common, and relatively harmless, only reaching the news in this case due to the association with Wikileaks.

 

Chengdu J-20 stealth fighter jet

When it was unveiled in January 2010, the Chinese engineered Chengdu J-20 stealth fighter jet was speculated by Balkan military officials and other experts as having been reverse engineered from the parts of a US F-117 Nighthawk stealth fighter shot down over Serbia in 1999. It was the first time such an aircraft had been hit. When the US jet was shot down, Chinese officials in the country were reported as having travelled around the region buying up parts of the aircraft from farmers. Representing 'dramatic progress' into cutting edge military technology for the Chinese, the Chengdu J-20 stealth fighter was thought to potentially pose a challenge to US air superiority. President Milosevic was known to have routinely shared captured military technology with Russian and Chinese allies. The Russian Sukhoi T-50 prototype stealth fighter, unveiled in 2010, is likely to have been built from knowledge based on the same source.

 

Chinese commentators contested claims this technology had somehow been stolen. A test pilot claimed that the J-20 was a "masterpiece" of home-grown innovation and that the F-117 technology was "outdated" even at the time it was shot down, although it was reported that one of the wheels of the J-20 actually fell off the aircraft during a demonstration.[citation needed] An unnamed Chinese defence official protested to the official English language mouthpiece of the Chinese Communist Party, the Global Times, "It's not the first time foreign media has smeared newly-unveiled Chinese military technologies. It's meaningless to respond to such speculations.

 

Concerns of Nation States

United States

A recent report to the US Government, by aerospace and defense company Northrop Grumman, describes Chinese economic espionage as comprising 'the single greatest threat to U.S. technology'.Joe Stewart, of SecureWorks, blogging on the 2009 cyber attack on Google, referred to a 'persistent campaign of "espionage-by-malware" emanating from the People’s Republic of China (PRC)' with both corporate and state secrets being 'Shanghaied' over the past 5 or 6 years.The Northrup Grumann report states that the collection of US defense engineering data through cyberattack is regarded as having 'saved the recipient of the information years of R&D and significant amounts of funding'.Concerns about the extent of cyberattacks on the US emanating from China has led to the situation being described as the dawn of a 'new cold cyberwar'.

 

United Kingdom

In December 2007 it was revealed that Jonathan Evans, head of the United Kingdom's MI5 had sent out confidential letters to 300 chief executives and security chiefs at the country's banks, accountants and legal firms warning of attacks from Chinese 'state organisations'. A summary was also posted on the secure website of the Centre for the Protection of the National Infrastructure, accessed by some of the nation's 'critical infrastructure' companies, including 'telecoms firms, banks and water and electricity companies'. One security expert warned about the use of 'custom trojans,' software specifically designed to hack into a particular firm and feed back data.Whilst China was identified as the country most active in the use of internet spying, up to 120 other countries were said to be using similar techniques.The Chinese government responded to UK accusations of economic espionage by saying that the report of such activities was 'slanderous' and that the government opposed hacking which is prohibited by law.

 

Germany

German counter-intelligence experts have maintained the German economy is losing around €53 billion or the equivalent of 30'000 jobs to economic espionage yearly. The main perpetrator was thought to be China, though Russia was also considered "top of the list," with a variety of espionage methods being used, from old fashioned spying, phone tapping and stealing laptops, to internet based methods, such as the use of Trojan email attacks. The target of these attacks included not just information about technology but also management techniques and marketing strategies. As well as accessing intellectual property on-line, state sponsored hackers were also considered, by German counter intelligence officer Walter Opfermann, as capable of "sabotaging huge chunks" of infrastructure such as Germany's power grid.

 

FTC Fair Information Practice

FTC- Fair Information Practices The United States Federal Trade Commission's Fair Information Practice Principles (FIPs) are guidelines that represent widely-accepted concepts concerning fair information practice in an electronic marketplace.

Introduction

FTC Fair Information Practice Principles are the result of the Commission's inquiry into the manner in which online entities collect and use personal information and safeguards to assure that practice is fair and provides adequate information privacy protection. The FTC has been studying online privacy issues since 1995, and in its 1998 report,the Commission described the widely-accepted Fair Information Practice Principles of Notice, Choice, Access, and Security.The Commission also identified Enforcement, the use of a reliable mechanism to provide sanctions for noncompliance as a critical component of any governmental or self-regulatory program to protect online privacy.

 

History and development

Fair Information Practice was initially proposed and named by the US Secretary's Advisory Committee on Automated Personal Data Systems in a 1973 report, Records, Computers and the Rights of Citizens, issued in response to the growing use of automated data systems containing information about individuals. The central contribution of the Advisory Committee was the development of a code of fair information practice for automated personal data systems. The Privacy Protection Study Commission also may have contributed to the development of FIPs principles in its 1977 report, Personal Privacy in an Information Society.

 

As privacy laws spread to other countries in Europe, international institutions took up privacy with a focus on the international implications of privacy regulation. In 1980, the Council of Europe adopted a Convention for the Protection of Individuals with Regard to Automatic Processing of Personal Data.At the same time, the Organisation for Economic Cooperation and Development (OECD) proposed similar privacy guidelines in the OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data. The OECD Guidelines, Council of Europe Convention, and European Union Data Protection Directive relied on FIPs as core principles. All three organizations revised and extended the original U.S. statement of FIPs, with the OECD Privacy Guidelines being the version most often cited in subsequent years.

Информация о работе Information protection policy