Skip Repetitive Navigation

To Department of Information Resources home pageState of Texas
Department of Information Resources
Leadership for Texas Government Technology

Texas state flag and capitol building composite
 
 
 
IT Security
Emergency Alerts
IT Security Services
Monthly Incident Reports
Reading Room
Policies, Standards & Guidelines
Continuity & Contingency Planning
IT Security Training
IT Security Contacts
Related Resources
SecureTexas - the online security resource for Texas citizens
 

Monthly Incident Summary Reports: September - November 2004

Links to other reports are available on the Security Reports Homepage.

Section 1: September - November 2004
Number of Agencies and Universities Reporting:

September 2004
OrganizationType Incidents No Incidents Total
Universities 34 19 53
Agencies 38 36 74

October 2004
OrganizationType Incidents No Incidents Total
Universities 38 16 54
Agencies 39 37 76
November 2004
OrganizationType Incidents No Incidents No Report Total
Universities 36
8
16
60
Agencies 41
7
42
90

Types of Incidents:

Types of Incidents September 2004 October 2004 November 2004
Actual Infections 3361 2037 11057
Unauthorized Physical Access 2 3 1
Unauthorized Information Access 11 27 48
Web Site Defacement 0 2 4
Theft of Equipment 2 1 25
Theft of Information 1 1 0
Unauthorized Use/Misuse 44 288 320
Accident/Planned Disruption 49 34 620
Disruption or Denial of Services (DOS) 20 67 8
Other 61510 218 980
Total 65000 2678 13063

Impact of Incidents:

Month Total Hours Downtime Hours Total Costs Lost Data
September 2004 1767 354 57855 2
October 2004 8566 3125 202231 1
November 2004 2516 327 177162 0

Incident Profiles:

Month Detected with IDS Internal Source External Source
September 2004 32515036 8712 344719
October 2004 24862856 4223 625544
November 2004 27082792 6988 27079100

Malicious Code:

Malicious Code September 2004 October 2004 November 2004
Viruses/Worms 1541600 14485016 5817486
Logic Bombs 0 0 2
Back Doors 18237 25876 13230
Other Malicious Code 53482 33415 53153
Actual Infections September 2004 October 2004 November 2004
Total Workstations/Hard Drives Infected 3351 2028 11024
Total Servers Infected 10 9 33

Server Types (Number of Systems):

Type of Systems September 2004 October 2004 November 2004
Critical production applications and/or data 2 9 26
Critical administrative/support applications and/or data 7 3 28
Research applications and/or data 1 3 24
Academic applications and/or data 7 12 28
External use web servers 4 9 11
Internal use web servers 13 2 6
FTP Servers 0 2 0
Email Servers 80607 65473 206754
Print Servers 2 7 10
Other Servers 270 80 30
Total 80913 65600 206917

Response Activities and General Information:

Question September 2004 October 2004 November 2004
1. Number of times were incident response plans activated 191 711 131
2. Number of times disaster recovery plans activated due to security incident 3 1 4
3. Average hours from detection to containment 694 1313 579
4. Incidents with response activity logs kept 628 742 1093
5. Damage to agency/university IR assets 11 5 13
5a. Number of Assets restored 93 84 32
6. Number of incidents needed outside assistance 2 7 8
7. Number of incidents resulted in new security measures 71 114 45
7a. Number of patches installed 463 713 234
7b. Number security software installed 16 74 34
7c. Number of additional policies developed 5 6 7
7d. Number other 1 3 6
8. Number incidents resulted in proliferation 79 88 229
8a. Internal Systems 65 80 97
8b. External Systems 17 8 136
9. Incidents resulted in external public awareness 6 6 5
10. Number Incidents reported to law enforcement 4 3 5

Top 10 Viruses
September 2004 October 2004 November 2004
Netsky Netsky Netsky
Bagle MyDoom Beagle
Beagle Lovgate MyDoom
Zafi Beagle Bagel
MyDoom BugBear Lovgate
Somefool Bagel BugBear
MIME Erkez Sober
Klez Sasser Zafi
Erkez Zafi Klez
Phish-Bank Fraud MIME MIME

 
  Texas State Seal  
 
  Department of Information Resources
300 West 15th St., Suite 1300
Austin, TX 78701 (Map & Directions)
1-512-475-4700
Privacy & Security Policy
Accessibility | Open Records Policy
Link Policy | Compact with Texans
DIR Contacts | dirinfo@dir.state.tx.us
 
 
Last updated November 18, 2005