Interested in learning more about cyber security training?
SANS Institute InfoSec Reading Room This paper is from the SANS Institute Reading Room site. Reposting is not permitted without express written permission.
Case Study: The Home Depot Data Breach The theft of payment card information has become a common issue in today’s society. Even after the lessons learned from the Target data breach, Home Depot’s Point of Sale systems were compromised by similar exploitation methods. The use of stolen third-party vendor credentials and RAM scraping malware were instrumental in the success of both data breaches. Home Depot has taken multiple steps to recover from its data breach, one of them being to enable the use of EMV Chip-and-PIN payment cards. Is the use of EMV paymen…
Copyright SANS Institute Author Retains Full Rights
AD
http://www.sans.org?utm_source=Print&utm_medium=Reading+Room+Paper&utm_content=Case_Study_The_Home_Depot_Data_Breach+Cover&utm_campaign=SANS+Training
http://www.sans.org/info/36909
http://www.sans.org/info/36914
http://www.sans.org/reading-room/click/657
Case Study: The Home Depot Data Breach | 1
Brett Hawkins, [email protected]
Case Study: The Home Depot Data Breach
GIAC (GSEC) Gold Certification
Author: Brett Hawkins, [email protected] Advisor: Christopher Walker
Accepted: January 2015
Abstract
The theft of payment card information has become a common issue in todays society. Even after
the lessons learned from the Target data breach, Home Depots Point of Sale systems were
compromised by similar exploitation methods. The use of stolen third-party vendor credentials
and RAM scraping malware were instrumental in the success of both data breaches. Home Depot
has taken multiple steps to recover from its data breach, one of them being to enable the use of
EMV Chip-and-PIN payment cards. Is the use of EMV payment cards necessary? If P2P (Point-
to-Point) encryption is used, the only method available to steal payment card data is the
installation of a payment card skimmer. RAM scraping malware grabbed the payment card data
in the Home Depot breach, not payment card skimmers. However, the malware would have
never been installed on the systems if the attackers did not possess third-party vendor credentials
and if the payment network was segregated properly from the rest of the Home Depot network.
The implementation of P2P encryption and proper network segregation would have prevented
the Home Depot data breach.
Case Study: The Home Depot Data Breach | 2
Brett Hawkins, [email protected]
1. Introduction On September 8th, 2014, Home Depot released a statement indicating that its
payment card systems were breached. They explained that the investigation started on
September 2nd and they were still trying to discover the actual scope and impact of the
breach. Home Depot explained that they would be offering free credit services to affected
customers who used their payment card as early as April of 2014 and apologized for the
data breach. They also indicated that their Incident Response Team was following its
Incident Response plan to contain and eradicate the damage and was working with
security firms for the investigation (“The Home Depot, Inc. – News Release,” 2014). This
is one of many retail breaches that have occurred and will continue to occur, until
retailers become proactive in safeguarding their environments.Strategic Use of Information Resources(Writing case analysis, from the attached case study)
Writing the case study
Generally, there are eight sections in a case study. Use this as a guideline to write your case study.
Synopsis/Executive Summary
Outline the purpose of the case study.
Describe the field of research this is usually an overview of the company.
Outline the issues and findings of the case study without the specific details.
Identify the theory that will be used to analyse the case study.
The reader should be able to get a clear picture of the essential contents of the study.
Note any assumptions made. You may not have all the information you would like, so some assumptions may be necessary
e.g. “It has been assumed that..
“Assuming that it takes half an hour to read one document..
Findings
Identify the problems found in the case.
Each analysis of a problem should be supported by facts given in the case together with the relevant theory and course concepts.
It is important to search for any underlying problems; for example, cross-cultural conflict may be only a symptom of the underlying problem of inadequate policies and practices within the company.
This section is often divided into sub-sections, one for each problem.
Discussion
Summarise the major problem/s.
Identify alternative solutions to this/these major problem/s (there is likely to be more than one solution per problem).
Briefly outline each alternative solution and then evaluate it in terms of its advantages and disadvantages.
There is no need to refer to theory or coursework here.
Conclusion
Sum up the main points from the findings and discussion.
Recommendations
Choose which of the alternative solutions should be adopted.
Briefly justify your choice and explain how it will solve the major problem/s.
This should be written in a forceful style as this section is intended to be persuasive.
Integration of theory and coursework is appropriate here.
Implementation
Explain what should be done, by whom and by when.
If appropriate, include a rough estimate of costs (both financial and time).
References
Make sure all references are cited correctly.
Appendices (if any)
Attach any original data that relates to the study, which would have interrupted the flow of the discussion in the main body.








Recent Comments