The recent and massive database breach at Equifax serves to highlight the insider threat that database systems face today. But you say, "The Equifax database attack was perpetrated by external hackers, not internal personnel." While that's true, it is also true that once the Equifax database attackers circumvented the corporate firewalls and breached the application, they were able to masquerade as legitimate and authorized insiders. To identify an attack of that nature requires tools that detect insider threats. To better understand all of this, let's walk through the Equifax database attack chain.
According to Equifax, the database attackers exploited a vulnerability in the third-party Apache Struts software they were running and had failed to patch with an available security update. Specifically the vulnerability is CVE-2017-5638 and a patch had been available to Equifax for nearly two months prior to the attack, yet for some unexplained reason, Equifax had never installed it.
Apache Struts is a very popular third-party web application software package that Equifax uses, as does 65 of the Fortune 100 companies. Through the vulnerability the attackers were able to submit operating system commands directly to the server. At that point the attacker, for all intents and purposes, appeared as a legitimate and authorized insider – a trusted administrator with all of the privileges assigned to the application. As an aside, we have a textbook example here as to why it's good security hygiene to restrict privileges of users and applications to the absolute minimum. A least privilege policy limits potential damage in the event the database credentials are compromised.
Complete your profile to continue reading and get FREE access to CUTimes.com, part of your ALM digital membership.
Your access to unlimited CUTimes.com content isn’t changing.
Once you are an ALM digital member, you’ll receive:
- Breaking credit union news and analysis, on-site and via our newsletters and custom alerts
- Weekly Shared Accounts podcast featuring exclusive interviews with industry leaders
- Educational webcasts, white papers, and ebooks from industry thought leaders
- Critical coverage of the commercial real estate and financial advisory markets on our other ALM sites, GlobeSt.com and ThinkAdvisor.com
Already have an account? Sign In Now
© 2024 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.