Welcome Guest. | Log In | Register | Membership Benefits

Teaming Up To Take Down Threats

Security professionals are leery of one-way public-private partnerships, but Operation Ghost Click shows that the model is necessary to take on international threats

Nov 10, 2011 | 04:20 PM | 

By Robert Lemos, Contributing Editor
Dark Reading


Policy makers and government officials have used the term "public-private partnerships" as a way to fight online threats so frequently that it has become code for doing nothing. Yet the recently announced Operation Ghost Click shows that such teamwork is necessary to take on cybercriminals and more advanced threats online.

On Wednesday, the FBI announced a massive investigation in conjunction with international law enforcement agencies, private industry, and nongovernment organizations, which led to the charging of seven Estonian and Russian citizens for a widespread click fraud scheme that had infected more than 4 million computers and netted the group more than $14 million.

The group, operating under various corporate names including Rove Digital, allegedly infected victims' computers with DNSChanger -- malware that changed the systems' domain-name servers, redirecting requests for Web site addresses through a network of criminal-controlled hosts. For four years, the group allegedly used the malware and servers to create false advertising clicks to businesses that paid affiliate fees, defrauding the firms. The Estonian police arrested the six Estonian nationals on Tuesday, while the sole Russian suspect remained at large.

"With the flip of a switch, the FBI and our partners dismantled the Rove criminal enterprise," said Janice K. Fedarcyk, the FBI's Assistant Director-in-Charge, in a statement. "Thanks to the collective effort across the U.S. and in Estonia, six leaders of the criminal enterprise have been arrested and numerous servers operated by the criminal organization have been disabled."

The scheme required massive cooperation to investigate and track the people perpetrating the fraud. The FBI worked with the Estonian Police and Border Guard, the Dutch National Police, and NASA's Office of the Inspector General. In the private sector, the law enforcement agency relied on resources at Georgia Tech University, the Internet Systems Consortium, security firm Mandiant, anti-spam group Spamhaus, security intelligence firm Team Cymru, antivirus company Trend Micro, the University of Alabama at Birmingham, and members of an ad hoc group of subject matter experts known as the DNS Changer Working Group.

The FBI even sought a partner to help manage the remediation efforts. Merely taking down the fraudulent DNS network's control servers would have likely resulted in the infected computers being cut off from the Internet until a knowledgeable person reset the computer's lists of DNS hosts. In this case, the rogue DNS servers were replaced by legitimate ones run by the Internet Systems Consortium, the nonprofit company that develops the widely used BIND domain-name system software.

Without such cooperation, the criminals and agents behind online crime and intellectual property attacks could not be investigated or prosecuted, says Phyllis Schneck, chief technology officer for public sector at McAfee.

"This is what happens when the good guys make it work," Schneck says. "This is what happens when several companies can get together with nonprofits and work together with law enforcement to go across corporate boundaries and across international boundaries. This was exceedingly well-orchestrated."

Without the limitation of legal and national boundaries, and frequently better at sharing information, online adversaries are typically much more agile than the defenders, and that's a key issue such partnerships need to address, says Schneck.

Without better cooperation and better information sharing, cybercriminals and espionage agents will continue to win, says Steve Santorelli, director of global outreach at Team Cymru and an ex-Scotland Yard detective. The FBI's successful cooperative effort is an excellent example of how to proceed, he says.

"It is a model for the future," Santorelli says. "Law enforcement has realized they can't do it on their own. And industry has realized that they can't do it on its own."

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.



Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

Dark Reading encourages readers to engage in spirited, healthy debate, including taking us to task. However, Dark Reading moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. Dark Reading further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS



Advanced Threats Reports

report How Did They Get In? A Guide to Tracking Down The Source of an APT
If you think that your organization hasn't been affected by an advanced persistent threat, you probably haven't looked hard enough. Identifying that your organization is under attack is difficult enough; determining the scope of infiltration and damage presents a whole new level of challenge. To effectively protect against APTs, security pros will need to employ an arsenal of tools in a coordinated fashion, as well as develop new understandings of and approaches to system and data exploits. Here's a short and simple guide to this challenge.

report Detecting and Defending Against Advanced Persistent Threats
APTs are a growing problem for enterprises big and small. Protecting your organization from these targeted threats requires constant vigilance, ongoing employee training and a concerted effort to align security systems to address every phase of an APT. Companies also need to develop a remediation and response plan if, despite best efforts, defenses are breached.

report Smarter, Stealthier, Sneakier Malware
Increasingly sophisticated and targeted attacks are making it more difficult for organizations to detect and defend against the latest malware. In this compendium of recent coverage from Dark Reading, you?ll get a look at some of the newest -- and most dangerous -- malware on the Web, and what you can do to stop it.

Other reports from the Advanced Threats Tech Center:

Related Content

MOBILE SECURITY - Mapping an Ecosystem of Risk
This white paper highlights the various considerations for defending mobile applications-from the mobile application architecture itself to the myriad testing technologies needed to properly assess mobile applications risk.

Software Security Delivered in the Cloud
This Solution Guide details the automated, turnkey service that requires no special security assessment expertise. It details HP's market-leading static and dynamic analysis technologies that help organizations worldwide gain insight into the security state of their essential business applications.

SANS Mobility/BYOD Security Survey
This survey, which includes input from more than 500 IT professionals, explores how organizations are managing risk around their end user mobile devices as well as what level of policies and controls enterprises have around mobile usage.

Expert Guide to Application Security - Real-time Hybrid Analysis
Explore the next generation of hybrid security analysis - what it is, how it works, and its benefits. This white paper details how hybrid application security enables organizations to resolve critical software security issues faster and at a lower cost than any other available technology.

A Mainstay Partners Study: Does Application Security Pay?
Measuring the Business Impact of Software Security Assurance Solutions: a study of 17 organizations that implemented solutions from Fortify Software, combining industry research and benchmark analysis to identify, qualify, and quantify the full range of benefits seen from their SSA investments.




Featured Webcasts
Featured Whitepapers
Featured Reports