Question

In: Computer Science

The Internal Revenue Service (IRS) annually processes more than 222 million tax returns. The returns are...

The Internal Revenue Service (IRS) annually processes more than 222 million tax returns. The returns are then converted into electronic records. The information contained in these records is protected by law and considered sensitive. Maintaining this type of information could make the IRS a target for computer hackers—individuals who attempt to gain unauthorized access to computers or computer networks.

The IRS has made significant efforts to secure the perimeters of its computer network from external cyberthreats. Because hackers cannot gain direct access to the IRS through these Internet gateways, they are likely to seek other methods. One such method is social engineering, which is the process of gaining information from people, often through deception, for the purpose of finding out about an organization’s computer resources. One of the most common tactics is to convince an organization’s employees to reveal their passwords.

In August 2001, with the assistance of a contractor, the IRS conducted social engineering tests on IRS employees. The IRS team placed calls to 100 IRS employees, asking them to change their passwords to what the team suggested. Of those employees called, 71 were willing to accommodate the team’s request.

The employees gave the following reasons for why they were willing to accommodate the request:

  1. They were not aware of social engineering tactics or the security requirements to protect their passwords.
  2. They were willing to assist in any way possible once the team members identified themselves as the IT help desk.
  3. They were having network problems, and the call seemed legitimate.
  4. Although they questioned the caller’s identity and could not locate the caller’s name, which was fictitious, in the global e-mail address book, they changed their passwords anyway.
  5. They were hesitant, but their managers gave them approval to assist the team.

a. Were any of these reasons valid?

b. What could the IRS do to mitigate the vulnerability?

Solutions

Expert Solution

a. Not all of the above reasons are valid.

The first reason where employees were not aware of the social engineering tactics or the security requirements to protect their passwords reflects that the above employees are either ignorant of the seriousness of their job or are ill-informed and not trained enough about the threats to the security.

The second reason where the employees helped because they thought that the call was from the IT help desk also acted impulsively as no IT help desk of an organization calls its employees about their passwords. Even in the case of any discrepancy, they first should have enformed their employers to airgap their access to their system before any change in the password was made so that no one should be able to misuse the credentials.

The third reason may seem genuine, but still, even in the case of network problem or failure, a precautionary step should be taken to separate the access of the individual's account from the whole network before any changes in the password are made.

The fourth reason shows that they are aware of the threats and are suspicious, but their action to ultimately give in the password shows that they are negligent of the protocols or there is a genuine absence of any preceding authority from which consultation or authorization can be taken in the case of occurrence of such discrepancies.

The fifth reason is a valid one, as it shows that in case of doubt the employees decided to approach their preceding authority who approved them to give their password. This shows that the employee is aware and the problem lies with the higher authority. It may even be the case of espionage or fraud at a higher level.

b. There are a few steps that can be taken by the IRS to mitigate the vulnerabilities.

1. Release a proper set of guidelines about security and protocols for performing authentication changes.

2. Perform a training session for all employees regarding the frauds.

3. Provide a specific set of procedures to follow before the change of password.

4. Provide an air-gapped system.

5. Use multiple levels of authorization before access credential changes.


Related Solutions

In the current tax year, IRS, the internal revenue service of the United States, estimates that...
In the current tax year, IRS, the internal revenue service of the United States, estimates that five persons of the many high network individual tax returns would be fraudulent. That is, they will contain errors that are purposely made to cheat the government. Although these errors are often well concealed, let us suppose that a thorough IRS audit will uncover them. Given this information, if a random sample of 100 such tax returns are audited, what is the probability that...
In the current tax year, IRS, the internal revenue service of the United States, estimates that...
In the current tax year, IRS, the internal revenue service of the United States, estimates that five persons of the many high network individual tax returns would be fraudulent. That is, they will contain errors that are purposely made to cheat the government. Although these errors are often well concealed, let us suppose that a thorough IRS audit will uncover them. Given this information, if a random sample of 100 such tax returns are audited, what is the probability that...
According to the Internal Revenue Service (IRS), the chances of your tax return being audited are...
According to the Internal Revenue Service (IRS), the chances of your tax return being audited are about 6 in 1,000 if your income is less than $50,000; 10 in 1,000 if your income is between $50,000 and $99,999; and 49 in 1,000 if your income is $100,000 or more (Statistical Abstract of the United States: 1995). If two taxpayers with incomes under $50,000 are randomly selected and two with incomes more than $100,000 are randomly selected, what is the probability...
The tax officials at the Internal revenue Service (IRS) are constantly working toward improving the wording...
The tax officials at the Internal revenue Service (IRS) are constantly working toward improving the wording and format of the tax returns. As part of a larger effort to help taxpayers, the Internal Revenue Service plans to streamline one of the forms into a shorter and simpler form for the 2021 tax season. Upon successful completion of this exercise, the new form, – about half the size of the current version – would replace the previous ones and will be...
The Internal Revenue Service sampled 20 tax returns and found that the average tax refund was...
The Internal Revenue Service sampled 20 tax returns and found that the average tax refund was $425.39 with a standard deviation of $107.10. Construct a 99% confidence interval for the mean value of all tax refunds. Why do we have a use a t-confidence interval instead of a z-confidence interval for this problem?
According to the Internal Revenue Service, 80% of all tax returns lead to a refund. A...
According to the Internal Revenue Service, 80% of all tax returns lead to a refund. A random sample of 100 tax returns is taken, and it was found that 83% of the tax returns in the sample require a refund. Using the sampling distribution of the proportion, calculate the probability that the sample proportion exceeds 85% in the sample of 100 tax returns? a. 0.1056 b. 0.2266 c. 0.2972 d. 0.0916 30. In a small town, there are 3,000 registered...
The Internal Revenue Service audits a random sample of 60% of tax returns where the gross...
The Internal Revenue Service audits a random sample of 60% of tax returns where the gross income exceeds $100,000. If a tax lawyer assists in the completion of 5 such returns, what is the probability that between 2 and 4 will be audited.
Pay your taxes: According to the Internal Revenue Service, the proportion of federal tax returns for...
Pay your taxes: According to the Internal Revenue Service, the proportion of federal tax returns for which no tax was paid was =p0.326. As part of a tax audit, tax officials draw a simple sample of =n140 tax returns. Use Cumulative Normal Distribution Table as needed. Round your answers to at least four decimal places if necessary. Part 1 of 4 (a)What is the probability that the sample proportion of tax returns for which no tax was paid is less...
According to the Internal Revenue Service, income tax returns one year averaged $1,332 in refunds for...
According to the Internal Revenue Service, income tax returns one year averaged $1,332 in refunds for taxpayers. One explanation of this figure is that taxpayers would rather have the government keep back too much money during the year than to owe it money at the end of the year. Suppose the average amount of tax at the end of a year is a refund of $1,332, with a standard deviation of $725. Assume that amounts owed or due on tax...
According to the Internal Revenue Service, income tax returns one year averaged $1,332 in refunds for...
According to the Internal Revenue Service, income tax returns one year averaged $1,332 in refunds for taxpayers. One explanation of this figure is that taxpayers would rather have the government keep back too much money during the year than to owe it money at the end of the year. Suppose the average amount of tax at the end of a year is a refund of $1,332, with a standard deviation of $725. Assume that amounts owed or due on tax...
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT