TMCnet News

Intrusic Explores How Hackers Use Legitimate Channels to Infiltrate Corporate Networks; ''Inside the Insider Threat'' Series Continues With an Overview of Island Hopping
[June 21, 2004]

Intrusic Explores How Hackers Use Legitimate Channels to Infiltrate Corporate Networks; ''Inside the Insider Threat'' Series Continues With an Overview of Island Hopping

WALTHAM, Mass. --(Business Wire)-- June 21, 2004 -- Intrusic, the first and only security software company to specifically target the insider threat, today announced the second part of its "Inside the Insider Threat" educational initiative that explores one of the most prevalent methods hackers use to infiltrate corporate networks--Island Hopping.

The Insider Threat is anyone--from hackers to disgruntled employees--who compromise organization's internal infrastructure and then set up shop undetected in the data center where they are free to steal, disrupt or damage valuable intellectual property, sensitive documents and personal or corporate information.

Island Hopping is one of the most common methods hackers use to illegitimately gain access to a corporate network while disguised as a legitimate user.


"Hackers who want a convenient way to infiltrate an enterprise or organization's network use 'Island Hopping' so they can enter network systems through the side door," said Jonathan Bingham, president of Intrusic. "This technique allows hackers to stealthily bypass firewall and IDS protections, without alerting anyone to their presence."

What is "Island Hopping?"

Island Hopping involves several steps. First, the hacker scans large network blocks (range of network addresses) looking for exploitable systems or already blocked systems. Network blocks allocated to broadband are a hacker's delight. Of these systems that are successfully exploited, some have virtual private network (VPN) connections that allow them to connect directly into their employer's network. Next, the hacker compromises the home system, which is generally less secure than a corporate network. After seizing the home computer, the hacker then is free to "hop" into the corporate network, utilizing the remote user's own VPN to bypass the firewall. Island Hopping converts the VPN from a security tool into a stealthy backdoor into the network.

Firewalls and intrusion detection systems rely on an underlying assumption that each user is authorized and legitimate and thus allow VPNs unchallenged access. In this way, traditional network defense technologies are powerless to stop Island Hopping since it does not violate access controls set up to protect the corporate network.

How Island Hopping Works

Island Hopping exploits the fact that enterprises and organizations allow employees trusted access to the internal corporate network from remote sites, business partners or home users. The hacker's goal is to compromise as many home user systems as possible in an automated fashion and then look for channels that lead into an enterprise's internal network. The scan generally results in a large number of susceptible systems, thus giving the hacker an entry point into the internal network of an organization. Most importantly, it is a trusted entry point, usually unobstructed by access control and typically not scrutinized by the IT or security teams.

Compromising an ISP in order to gain access to customer networks can easily yield large numbers of legitimate credentials. One recent study revealed 4,466 username/password pairs for roughly 1,000 remote organizations, 104 root accounts - of which one was a master password for the IT organization of a global company.

About Zephon

Zephon copies traffic from the internal network and then deploys sophisticated, corollary analysis to determine if host systems have been compromised. The result of the analysis is a complete, easy to understand assessment of the nature, scope and extent of a compromise providing companies with all of the tools necessary to prevent damage to the business. Zephon is the only product capable of detecting the dangerous action of "sleeper cells" which employ techniques such as stateless attacks - commonly regarded as the stealthiest way in and out of an organization's network.

Zephon is commercially available now. Pricing is set on a per-server licensing fee. For more information, contact Intrusic at [email protected].

About Intrusic

Intrusic, Inc., based in Waltham, Mass., was founded by a group of security experts in 2002 to create solution to one of the most insidious threats to global networks, the "Insider Threat." The real danger to enterprises, organizations and governments goes beyond perimeter attacks, but to unauthorized intruders already inside networks engaging in "noiseless action," the execution of internal espionage. Intrusic's world-class executive team has developed Zephon, a ground-breaking solution to identify compromised networks and map the full extent of the breach by providing full forensics. For more information visit us at www.intrusic.com

[ Back To TMCnet.com's Homepage ]