2013: Year of the Salami Attack!

Updated happygeek 0 Tallied Votes 399 Views Share

According to security experts at data governance outfit Varonis, 2013 will be the year of the salami attack. On the plus side, they also predict that the world will not come to an end on December 21st 2012.

It's not just salami that your business needs to worry about in terms of tech though. Varonis also points towards challenges such as the growing gap between people in a company who know how to find information and those who do not (the importance of intelligent internal search, retention and data archiving), the growing gap between how people use technology at work and at home (who owns the IP of a document created on a personal device, for example?) and the closing collaborative gap (business needs to collaborate with third parties in the same efficient way they do with internal partners).

But that's all by the by, anyone reading this is probably wondering just what the heck a salami attack is and conjuring up images of a masked man hitting the servers with a spicy sausage. Thankfully, Varonis co-founder Yaki Faitelson can clarify: "A bit like a sandwich is pieced together one ingredient a time, we believe that the vast expanse of information about employees and business partners poses a new and very real threat to organisations. All the individual scraps of information about an individual online can be researched and pieced together to create a complete picture – who they are, where they work, what school their children attend. It’s all there waiting to be plundered and the primary thing that saves most people is nobody is looking for them. But what if someone were? It’s important that, as an organisation, you make sure your employees – especially those in key positions, are made aware of the risks. Consider collecting the information that’s easily accessible on one employee to demonstrate what can be done to really bring the message home."

Dani AI

Generated

Short primer and pragmatic checklist.

The phrase “salami attack” is an analogy, not a snack-based threat: it describes attacks or frauds made up of many tiny, hard-to-notice actions whose sum becomes significant. That can be classic “penny‑shaving” financial fraud or modern data/metadata aggregation that turns harmless fragments into a high‑value dossier. (See general background on the concept.)
Salami slicing tactics

Context from the thread: rightly points to vendor warnings; and joked about salami, and urged calm — but real incidents exist. A documented case involved automated creation of tens of thousands of accounts to collect micro‑deposits, netting the attacker tens of thousands of dollars in small increments; that behaviour is exactly what the term warns about.
Hacker takes $50,000 a few cents at a time (example)

Practical, immediate steps for organisations (short checklist):

  • Enforce least‑privilege and separate duties for transaction/billing systems; remove standing admin rights.
  • Put privileged access behind a PAM workflow (just‑in‑time, vaulted credentials, session logging).
  • Centralise and protect logs; build correlation rules that look for repeated micro‑differences and many small transfers to the same destination.
  • Run automated daily/weekly reconciliations that flag cumulative discrepancies, not just single large errors.
  • Apply continuous monitoring and UEBA rules so slow, low‑volume exfiltration or rounding anomalies show up as anomalous patterns.
  • Include insider‑risk processes: policy, reporting, and regular program evaluation.

Guidance on logging, continuous monitoring and insider programs is covered by NIST and CISA best practices.
NIST: Guide to computer security log management (SP 800‑92)
NIST: Information Security Continuous Monitoring (SP 800‑137)
CISA: Insider Risk Mitigation Program Evaluation (IRMPE)

If time is tight: enable MFA, restrict who can change billing/rounding code, add SIEM alerts for repeated sub‑cent or sub‑dollar movements to the same account, and schedule a targeted reconciliation of the last 12 months.

ratubetting 0 Newbie Poster

hmm.. i thinks not get seriously of this..

just relax :)

Member Avatar for Member #949455
Member #949455

But that's all by the by, anyone reading this is probably wondering just what the heck a salami attack is and conjuring up images of a masked man hitting the servers with a spicy sausage.

I love to eating salami with swiss chesse. I'm no quite understand why salami is related to IT news.

<M/> 170 Why so serious? Featured Poster

I'm no quite understand why salami is related to IT news.

Because IT people like eating salami, it is their fuel (well, at least not for me...)

Member Avatar for Member #949455
Member #949455

Because IT people like eating salami, it is their fuel (well, at least not for me...)

I'm not sure about that. But salami is good.

<M/> 170 Why so serious? Featured Poster

Well, your an IT person (or at least your knowledge of it is significantly higher than most of the daniwebbers) and you eat salami and enjoy. So you question is answered... Salami is relevant to IT.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.