Energy News  
Networking: Foiling e-Document Hackers

Danger lurks along every pathway in cyberspace.

Chicago (UPI) July 18, 2005
A worker sends an office colleague an e-mail with a corporate document attached, but the seeming routine message turns out to harbor a malicious passenger, because the attachment contains hidden pornographic images that were inserted by a hacker during it's transmission over the Internet. When the document is opened by a female employee, she files a lawsuit for sexual harassment.

This particular case is hypothetical, but the situation is real, experts told UPI's Networking. It is something increasingly plaguing corporate networks. To combat the problem, experts said, companies are going to have to monitor workflow, set new policies and install IT to intercept illicit content.

The problem is, many companies skip the first step, which involves evaluating work practices and noting how and where secure knowledge is transferred, before investing in IT, said David Drab, director of information content security services at Xerox Global Services.

"By conducting a company-wide risk assessment, organizations can identify the information that represents the greatest threat to the company, if exposed," said Drab, who is also a former FBI agent.

As soon as the document-management policy is set, company networks need IT to maintain the integrity of documents that flow over the network. One solution is from a software developer in San Francisco called Workshare.

The company's software, Trace! Version 2, is a free metaware utility for Microsoft Office users that automatically alerts them to the risk level of the documents they are about to open. The software scans for sensitive or inappropriate content, both visible and hidden, within electronic documents.

"Each year, trillions of documents are exchanged electronically," said Ken Rutsky, Workshare's executive vice president for worldwide marketing. "There are serious compliance risks and liabilities over the exposure of personal private data, and other sensitive information."

The risks are increased, due not just to potential lawsuits from employees who feel violated by obscene links in a document, but also to certain laws. The federal Sarbanes-Oxley and Gramm-Leach-Bliley acts, as well as the California Breach Law, require that certain information be kept secure for reasons of financial disclosure, intellectual property management, privacy and identity, and related matters.

For example, if a document contains the word "confidential" in a header or footer, it probably contains corporate secrets and should be handled with care. If the word is in the text body, it probably is more benign. Content- filtering software can determine whether the file contains benign or sensitive information before someone opens it.

A recent survey of 332 large American enterprises conducted by Proofpoint in Cupertino, Calif., a software security firm, found stopping such leaks was the top concern for those who manage outbound e-mail. More than 35 percent of companies surveyed had investigated a suspected e-mail leak of confidential or proprietary information over the past year.

For example, a proprietary customer list may exist in an Excel spreadsheet, but if the document is converted to a PDF, it might be easier to smuggle it out of the company.

So, software developers are developing "audit trails" for individual documents, such as Excel spreadsheets and Microsoft Word word processing files, so each modification to a file can be monitored along the way. The software includes encryption and authentication measures so the "sending and receiving parties can be tracked from start to finish of the transfer process," said a spokeswoman for Tumbleweed in Redwood City, Calif., a maker of enterprise-class secure managed file-transfer software.

Gene Koprowski is a 2005 Lilly Endowment Award Winner for his columns for United Press International. He covers networking and telecommunications for UPI Science News.

Community
Email This Article
Comment On This Article

Related Links
SpaceDaily
Search SpaceDaily
Subscribe To SpaceDaily Express
Cyberwar - Internet Security News - Systems and Policy Issues



Memory Foam Mattress Review
Newsletters :: SpaceDaily :: SpaceWar :: TerraDaily :: Energy Daily
XML Feeds :: Space News :: Earth News :: War News :: Solar Energy News


US Military Mounts International Psyops Campaign
Washington (AFP) Dec 14, 2005
The US military is mounting a 300 million dollar psychological operations campaign to sway international opinion of the US war on terrorism through messages placed in foreign media, officials said Wednesday.







  • Portugal Turns To Wind Farms To Reduce High Oil Dependency
  • Purdue Findings Support Earlier Nuclear Fusion Experiments
  • GlobeTel Announces Research Effort On Fuel Cells With Proton Energy Systems
  • BP Teams Try To Level Listing 'Thunder Horse' Oil Platform

  • South Africa To Convert Nuclear Research Reactor
  • Singh, Bush Agree To Step Up Nuclear Cooperation Under 'New' Partnership
  • EU May Be Ready To Help Iran Build Nuclear Reactors: Negotiator
  • Russia, Iran Probe Former Russian Minister Over Nuclear Plant Embezzlement

  • Scientists Seek Sprite Light Source



  • Organic Farms Use Less Energy And Water
  • EU Governments Keep National Bans On GMOs
  • Insects Resistant When Single And Double-Gene Altered Plants In Proximity
  • Insects Developing Resistance To Genetically Engineered Crops

  • Eco-Friendly Motor Rally Sets Off From Kyoto To Celebrate Environment

  • Northrop Grumman to Help NASA Define Requirements for Quiet Sonic Boom Research Aircraft
  • Boeing and Honeywell Sign Contract for Innovative Supply-Chain Solution
  • Raytheon, Cessna Receive NASA Sonic Boom Research Grants
  • New Low Cost Airlines Take Flight In India

  • NASA plans to send new robot to Jupiter
  • Los Alamos Hopes To Lead New Era Of Nuclear Space Tranportion With Jovian Mission
  • Boeing Selects Leader for Nuclear Space Systems Program
  • Boeing-Led Team to Study Nuclear-Powered Space Systems

  • The content herein, unless otherwise known to be public domain, are Copyright 1995-2006 - SpaceDaily.AFP and UPI Wire Stories are copyright Agence France-Presse and United Press International. ESA PortalReports are copyright European Space Agency. All NASA sourced material is public domain. Additionalcopyrights may apply in whole or part to other bona fide parties. Advertising does not imply endorsement,agreement or approval of any opinions, statements or information provided by SpaceDaily on any Web page published or hosted by SpaceDaily. Privacy Statement