Most Popular White Papers
A Threat of 'World War Web'
Risk & Insurance, Dec, 2001 by Lori Widmer
* Review your insurance program for potential gaps or limitations in coverage. Consider whether a specific cyber-risk or other policy is appropriate or eliminate or reduce these uncovered exposures through other means.
RELATED ARTICLE: One Way Terrorists May Communicate
In the war against online terrorism, security firms are dealing with another method of attack--steganography. Steganography is using existing computer files, most often graphic images, to hide messages. According to FBI reports, steganography is believed to be used by Osama bin Laden to communicate with his followers via the Internet.
"Steganography is the method of inserting messages inside existing data," says Erik Laykin, president of Online Security Inc., Los Angeles. Computer files often contain empty areas or insignificant data. Encrypted messages can be placed inside these areas and be accessed easily and without detection. Laykin outlines how it works. "There are several tools available online for free with which to do it. They will hack into a site, copy an image on your Web site, then deconstruct the image using steganographic tools, insert a message into that image, reconstruct it, hack back into the site, and load it up onto the site."
Why would anyone go to this trouble? "It's quite simple. In the case of bin Laden, the intelligence services have been monitoring his communications via satellites and other tools for years. If he picks up a telephone, we're going to hear him. If he sends a fax, we're going to intercept it. He may have figured out that via steganography, he can get on the Internet, place a message on any accessible public Web site, and whoever he's trying to get the message to knows where to look for it. And we don't have any way of tracking this."
Until now, that is. Online Security's Online Labs division is designing free software, expected to be released by this printing, that will scan and search for Web sites that have been altered by steganographic means.
COPYRIGHT 2001 Axon Group
COPYRIGHT 2008 Gale, Cengage Learning