Book Review: An inside guide to hacking.

A new book shows how experienced hackers work and offers tips to help IT managers improve defences and gather evidence

Written by Iain Thomson

As a child, Neil Barrett was captivated by computers. He learnt to hack at an early age but after tiring of the thrills of hijacking radio telescopes and other systems online, he moved on to what proved to be a more interesting area - hacking the hackers. He has detailed some of his activities in his latest book, Traces of Guilt.

This book is a guide to the mentality of the hacker, the methods used to find and catch them, and the rules for dealing with computer evidence and the police. It is also a pretty good potted history of the major computer crimes of the past eight years.

The book opens with an account of one of Barrett's first cases as a computer investigator in an online paedophilia case. It highlights just how muddled legal and police professionals used to be about computer crime. It serves as a counterpoint for the rest of the book.

Barrett, a regular IT Week columnist, establishes his own credentials early on and uses his own experience to delve into the mind of the hacker. Why do hackers continually try to break into the seemingly unbreakable and what methods can they use? As it turns out it is much like the mindset of a computer gamer, who knows there must be a way to win and so tries everything to do it.

In subsequent chapters Barrett details investigations that illustrate the types of crime that are enabled by computer technology. These offences range from those involving online pornography to hacking, internet blackmail and identity fraud.

There is a lot here to make the security-conscious IT manager think. In one case Barrett demonstrated his talents by hacking a firm's server in four days based on nothing more than a business card. His involvement in the investigation of the Gary Glitter internet paedophilia case also makes fascinating reading.

Running through all these examples are a few themes that could help IT managers combat computer crime.

The first concerns the collection of evidence - just as investigators try to preserve the evidence at murder scenes, IT managers must be careful to keep the evidence at scenes of computer crimes. But time and again Barrett details cases where investigations were hampered or even killed because evidence was mishandled. For those concerned about hacking on their networks this is essential information for a successful conviction.

Second, Barrett recommends looking not just at suspicious data, but at suspects' actions, to build a profile of their methodology. This can increase the chances of apprehending suspects, and may lead the investigator to new areas of research to build a better case. This kind of "personality mapping" is already in use and is a skill all security experts should learn.

If there is a criticism of this book it is that uneven editing has left it a little disjointed. Barrett is a compelling writer but poor indexing means those who are not prepared to sit down and read the whole book will miss important points.

Barrett finishes the book - rather abruptly as it turns out - with a warning. The advent of wireless communications opens up a new range of security problems; and many companies with perfect physical security are letting themselves down electronically. It is a point worth making, because not enough firms seem to be aware of the danger at present.

Tags:

reader comments

related articles

Security

Security

The latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack. 15 Apr 2004

 

IT staff offered fast-track hacker course

Put yourself in the cyber-criminals' shoes and protect your network from attack 05 Mar 2004

related whitepapers

today's top stories

Middle East seeks progress through IT

There is growing awareness in the region of how technology can benefit society 05 Dec 2008

Scared of working from home?

Has anybody else noticed how full commuter train station car parks are at the moment? Perhaps some employees are trying to get... 05 Dec 2008

CIOs must embrace collaboration tools

Author Don Tapscott gives Angelica Mari his reasons for promoting social networking tools and says transparency is the key to security 04 Dec 2008

On a quest to build a connected society

BT Design’s JP Rangaswami talks to Gareth Morgan about his pivotal role in the telecoms giant’s efforts to deliver universal broadband and his plans to tap into the creativity of the open source community 04 Dec 2008

Should CRM be more sociable?

As vendors rush to add more social networking bells and whistles to their CRM products, some experts warn that users must tread carefully when venturing into online communities 03 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Should the government cut costs by scrapping major IT projects?

Should the government cut costs by scrapping major IT projects?

Tell us what you think

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

JP RangaswamiAnalysis

On a quest to build a connected society

BT Design’s JP Rangaswami talks to Gareth Morgan about his pivotal role in the telecoms giant’s efforts to deliver universal broadband and his plans to tap into the creativity of the open source community 04 Dec 2008

Doctors looking at a computerAnalysis

Watchdog wants IT to cure privacy woes

Information Commissioner Richard Thomas is urging organisations to put privacy protection at the top of their procurement and development criteria 04 Dec 2008

Advertisement

Primary Navigation