Newsletter 
July 25, 2008
Search 
Home
News
Industry Verticals
BFSI
Education
Energy
Government
IT
Manufacturing
Pharma
Retail
Services
Telecom
Events
Tech Insight
Market Scan
Interview
Case Study
CXO Lifestyle
White Papers
Editorial
CXO Views
Tech Terms
   FOCUS AREAS
 • Business Apps  
 • Mobility

 • Open Source
 • Security
   TECH INSIGHT
Harnessing the Information Overload
Today information is being generated at a fast pace, making it difficult to manage data explosion. Seema Ambashtha, director (database sales consulting) of Oracle India discusses about this information overload and what IT managers should do to dra More...
    MARKET SCAN
India Flying High in Workforce Development
Despite low science and engineering student graduation rates, and widely varying education quality, India is rapidly becoming a global R&D hub. According to an Ewing Marion Kauffman Foundation study, India's private sector has overcome its education system's deficiencies by adapting and perfecting the best practices of Western companies More...
   TECH TERMS
  • Blue Tooth
  • BI
  • CDMA
  • CRM
                             More...
Home > News > Technology
Email Print View Comments   

Ethical Hacking
By CXOtoday Staff
Mumbai, Apr 14, 2008

Internet has changed the way we communicate, the way we do business - creating a virtual world, allowing people to explore different avenues, which they never thought existed. Its growth is phenomenal to the extent - that for most of us life comes to a standstill without net. But on the flip side, this growth has only exposed us to security threats, particularly businesses that have become exposed to the world through web.

With businesses growing global and processes controlled over network, the Internet is playing host to a number of security loopholes like hacking, identity and data theft over the web, etc.

Hackers are getting smarter day-by-day, crafting sophisticated tools to steal confidential information of companies, breaking into sites - the list can go on and on.


These incidents have become rampant in the recent time.

Businesses, ranging from start-ups to large companies, have experienced the consequences of hack acts. In spite of putting the best security practices at place, many of them fail to shield their organizations against these threats.

So, is creating a firewall, encryption, or having an antivirus enough? With best of security policies getting easily hacked by cyber crooks, well this question isn't very difficult to answer.

So, how do organizations tackle the security issues? Dominic K, head (Global Operations) of Orchidseven Infosec explains, "Any organization today comprises multiple layers of systems, which enable their business across the globe. This is bound to include servers and network. Such network needs to be constantly tested to keep tab on the various possible vulnerabilities, which may hamper the business through various means - such as identity and data theft."

This clearly indicates that deploying firewall, Intrusion Detection System (IDS), Intrusion Prevention System (IPS), etc., is not adequate to ensure data or network security. Companies need trained IT professionals, professionals who can fix the security holes before the bad guys (read as black hat hackers) cause irreparable damages.

Few years back, some of you may remember, Abhishek Bacchan played the role of an ethical hacker in 'Om Jai Jagdish,' a Bollywood movie. He uses his hacking skills to create a program to actually block hackers instead. Well, this was not one of those fictitious roles confined to silver screen only. In fact, today ethical hackers constitute an important part of technical staff, as they can think like the hackers and prevent serious computer-related crimes.

So to discuss more elaborately, ethical hackers, or more popularly known as white hat hackers, helps organizations understand the present hidden problems in their servers and corporate network. White hackers, unlike those bad guys, use their skills to detect flaws within the company's security system so that they can be rectified quickly. They use the same skills like those of hackers, but legitimately. This is a major reason, why more companies are actually employing ethical hackers as part of their technical support staff.

Dominic explains, "Right from ERP package to network printers, workstations to firewalls - need to be tested for in-depth security. Such tests are must for every enterprise - irrespective of their vertical or domain. Penetration test, alias ethical hacking, must be conducted periodically. It s much needed for network self-diagnosis and self assessment."

However, it's crucial that companies follow certain norms while appointing ethical hackers. Businesses should test the approach skills of candidate toward security and ethical hacking. According to Dominic, a good ethical hacker should be able to:

1.Design and create plan methodologies
2.Should comprehend social engineering aspects used for fraud
3.Use latest techniques to hack into systems and networks
4.Understand digital forensics
5.Be aware of IT Act Law 2000, and other international laws with regards to information and data security
6.Understand reverse engineering and application security

Also ethical hackers need to follow certain policies. Like, an ethical hacker shouldn't indulge in personal agendas, which means whatever they do should support company's policies and goals. They should never use confidential information of companies for their own personal benefits. A professional white hat hacker will always approach the concerned manager, in case of any further clarification or problem.

Countries all around are vulnerable to cyber attacks. So, they are realizing the importance of ethical hackers. However, it's quite pity that the issue of e-security hasn't picked up the way it should have been. Hence, ethical hacking is not very popular yet. But, many companies, particularly some big enterprises are realizing the criticality of the situation. They're no longer unaware of the fact that India is most susceptible to cyber attacks.

But what's the reason behind this ignorance? Explains Dominic, "In the current scenario almost every organization, irrespective of its size is aware of the implications and consequences. However, there are few organizations that will be proactive than be reactive to such incidents."

"Although the Indian government has rolled out multiple plans and projects on e-commerce, yet few are completely secure. Today, almost 80% of government websites are vulnerable to such attacks. Theses hacks range from silly SQL injection to XSS attacks," he added.

The severity of the situation, hence, gives rise to an important question. Can Indian business organizations afford to remain ignorant? When hackers are increasingly compromising companies information, data for their own benefit, can businesses just wait and watch?

Of course not. It s time businesses should make ethical hacking as part of technology consulting. More and more awareness programs should be organized for everyone in the enterprise. The onus lies on top management, and the CXOs to train and keep their employees well-informed on vulnerabilities, and induct efficient ethical hackers in their organizations.

Related Links:

Broadband Boosts Internet Usage in APAC

Home  |  Technology  
Share and Connect   del.icio.us del.icio.us   Digg.com Digg.com   Myweb MyWeb   Newsvine.com Newsvine.com
 
 
Comment :

Name :
Company :
City :
E-mail :
Word verification : Type the characters you see in the picture below.
 
Characters are not case-sensitive
   

Comments
Report as offensive
I am intersted in ethical hacking and want to join
-
sagar m yet a student mumbai
06/07/08 08:43 PM
Reply
Report as offensive
Really nice explanation.Author has a vision. It is the rt time that v folks get ready for discussing n implementing e security solutions. For that v need to think like the black hackers do.
-
sanjay OFB kolkata
06/05/08 11:00 AM
Reply
Report as offensive
kkkkkkkkkkkkkkkkkkkkkkk
-
sagar Anonymous bhopal
30/04/08 02:36 PM
Reply
Report as offensive
i wanna become aethica haker
-
sagar Anonymous bhopal
30/04/08 02:33 PM
Reply

Disclaimer
ITNation (India) Pvt. Limited and its sites: www.channeltimes.com, www.techtree.com and www.cxotoday.com provide Comments and discussion boards as a professional medium for the various businesses of the IT industry to discuss business problems. Gossip, personal attacks and unsubstantiated charges are prohibited. Messages posted on this Web site as discussion threads or Comments (Content) are solely the opinions of their creators and do not necessarily reflect the opinions of ITNation (India) Pvt. Limited or its sites www.channeltimes.com, www.techtree.com and www.cxotoday.com.
All individuals who post material to this web site are solely responsible for all Content that they upload, post or otherwise transmit via the Web Site.
ITNation cannot vouch for the authenticity of the user or company names or e-mail addresses associated with posted messages. Under no circumstances will ITNation India Pvt.Ltd. or Cxotoday.com be liable in any way for any Content, including, but not limited to, for any errors or omissions in any Content, or for any loss or damage of any kind incurred as a result of the use of any Content posted or otherwise transmitted via the Bulletin Boards.
ITNation reserves the exclusive right to edit or remove messages containing inappropriate language or other material that could be construed as libelous, potentially libelous, or otherwise offensive or inappropriate. Discussion forums, bulletin boards and chat facilities are provided by ITNation solely for the convenience of those who make use of the service. ITNation does not endorse the products and services or other offerings mentioned in messages.
TODAY'S HEADLINES
Delhi Wi-Fi
Lodha Group Outsources
Sanovi India Operations
BPOs Tap Domestic
Netmagic Opens New Data
    CXO VIEWS
Rules for Sustainable Application Integration
Most organizations are expanding their application suites to meet growth, which in turn accelerates the need for integration of information or processes to leverage the real benefit of enterprise application suites. Hemen Goswami, CTO of Infogain provides insights on the benefits of enterprise integration to meet the organizational needs More...
LATEST COMMENTS
well i need cc track 1 and 2, wu login, ..
The readiness and optimal performance are ..
I will give excellent training in BASE and ..
Is there any version of Tally for business mobiles
hello madam we would like to com and sty ..
MOST POPULAR STORIES
McAfee Conducts S.P.A.M (5)
HCL Connect India&Africa (2)
Blue Coat Eyes (2)
Ctrl S Bags Certificate (2)
A Virtual Wallet (2)
Feedback | Sales Offices | Advertising Options | About CXOToday | Site Map |
Copyright (C) 2008 ITNation India Pvt. Ltd. All Rights Reserved.