War Gaming: Necessary Exercises

In the old days, there were white hat hackers who put their skills to use helping organizations understand and prevent vulnerabilities. At Intel, there's a 21st century version playing out under the auspices of Intel's Information Security team. Read how Intel approaches war gaming and creates a companywide security force.

Several times a year, Intel employees meet and plot how to hijack shipments of microprocessors, sell our intellectual property to competitors, blackmail our coworkers, and hack our networks. And we pay them to do it. We even provide lunch.

This is war gaming. For a few days we give the group a hypothetical target-some asset we want to protect - and ask them to think like blackmailers, hackers, terrorists, and hijackers. Intel's Information Security team uses those malicious plots to identify holes in our defenses and patch them, so that Intel assets remain safe.

Who are Threat Agents, and What Do They Want?
We have identified numerous archetypes, called threat agents, that differ in intent, capability, and resources. They all endanger your assets.The lone teenage hacker proving his acumen is a stereotype from the 1980s (think of Matthew Broderick in the 1983 film called, coincidentally, "WarGames"), and is a minor threat today. Now, other threat agents like terrorists and disgruntled employees are out to cause your company embarrassment or financial damage. Organized crime or hostile governments might want your property or secrets for resale. An attacker might be part of a well-resourced, ultra-sophisticated syndicate, or a lone opportunist from inside your company.

But not all threat agents are attackers. Some are simply untrained employees who create security gaps, or honest people with more network access than they require to do their jobs.

Every threat agent, hostile or not, endangers a company's assets. For a bank, the asset is obviously money. For a tobacco company, it is cartons of cigarettes, and for years those companies were targeted by hijackers who knew when and where to intercept trucks.

Intel produces microprocessors, which are like gemstones in terms of high value in a small package. So our assets are our products, as well as our product designs, high-value equipment, financial databases, and employee records. Indeed, employee records are a very attractive target for organized crime intent on identity theft.

 

Sponsored Content

Sign In

Please sign in and you will have access to all the content available on CIO.in

Username


Password




Forgotten password?

One Time Registration Only !

Register now For your free CIO.in account and avail the following key benefits:
  • Never fill up any form to download whitepapers and case studies
  • Special invitations to CIO events
  • Be the first to get CIO reports & analysis
  • CIO special offers... and much more!
white paper

Strategic Business Process Management in the Cloud: Optimize Business Processes in the Cloud with Intelligent Business Platform

Cloud computing has become the most transformative technology shift since the personal computer—and then the Internet. Migrating business to the cloud has reached a tipping point, where it is no longer a trend but rather an absolute business requirement. This white paper from IBM looks at how you can optimize your business processes in the cloud with a next generation BPM strategy.

white paper

Competitive Review of BPM in the Cloud

Platform as a Service is an attractive deployment for Business Process Management [BPM] for a number of reasons; ease of use, low cost, easy to support, and rapid delivery. But which vendor offers the right Cloud-based BPM solution for your needs? This Lustratus Research paper from IBM provides a high level review of BPM on cloud capabilities from IBM, Appian, OpenText and Pegasystems.

white paper

IT Executive Guide To Security Intelligence: Transitioning from Log Management and SIEM to Security Intelligence

In this white paper, you will learn how security intelligence, powered by next-generation SIEM and log management, enables organizations from Fortune 500 companies to mid-sized enterprises to government agencies to maintain comprehensive and cost-effective information security. Also you will discover how security intelligence is the critical next step for organizations that recognize the importance of information security.