Attacks/Breaches
11/3/2011
02:10 PM
50%
50%

Feds Cite Chinese Cyber Army Capability

U.S. government report blames China and Russia for cyber theft of U.S. economic secrets, but one expert questions China's actual hacking capabilities.

10 Massive Security Breaches
(click image for larger view)
Slideshow: 10 Massive Security Breaches
The U.S. government continues to point the cyber-attack finger at China and Russia, but at least one academic is questioning the actual capabilities of China's cyber army.

The most recent U.S. government accusations came on Thursday, with the release of a report to Congress from the top U.S. counterintelligence agency. The report's title, "Foreign Spies Stealing U.S. Economic Secrets in Cyberspace," left little doubt as to its findings. All that was left was to identify the foreign governments in question.

"Chinese actors are the world's most active and persistent perpetrators of economic espionage," according to the report, released by the Office of the National Counterintelligence Executive. And, "Russia's intelligence services are conducting a range of activities to collect economic information and technology from U.S. targets."

[ How much of a threat are the Chinese? Chinese Military Blamed For Hacking U.S. Satellites. ]

"Trade secrets developed over thousands of working hours by our brightest minds are stolen in a split second and transferred to our competitors," said national counterintelligence executive Robert "Bear" Bryant, at a press briefing that detailed the report's findings, reported The Washington Post.

While the annual counterintelligence report has been released since 1995, this is the first year that a report has emphasized "foreign collectors" exploits. According to news reports, administration officials said that was because of the severity of the problem.

Part of the issue, of course, is that nearly all business-critical information today gets stored digitally, which makes for a larger online attack target than ever before. Unlike the old days of espionage, online attackers also face few personal risks when they try to procure digital data. "Cyberspace makes it possible for foreign collectors to gather enormous quantities of information quickly and with little risk, whether via remote exploitation of victims' computer networks, downloads of data to external media devices, or email messages transmitting sensitive information," according to the report.

But China and Russia aren't the only countries being blamed. In fact, U.S. allies are also gunning for sensitive data, sometimes using social engineering attacks to get it. "Some U.S. allies and partners use their broad access to U.S. institutions to acquire sensitive U.S. economic and technology information, primarily through aggressive elicitation and other human intelligence tactics. Some of these states have advanced cyber capabilities," said the report.

But how bad is the actual threat? In the wake of reports such as this one, observers sometimes accuse the government of inflating cyber threats, in part due to agencies positioning themselves to be the future guardians of the nation's cyber defenses, in light of the potential for massive, related appropriations from Congress.

If China has unleashed a massive intelligence-gathering campaign against the United States and its close allies, however, what can be done about it? For starters, leading government and private sector CIOs have called on the government to improve its threat intelligence information-sharing efforts with the private sector, to help businesses more easily spot advanced persistent threats that can target just a handful of computers at a small number of companies, yet succeed.

Information aside, some of the blame for China's success at spying may go to U.S. businesses simply not being serious enough about information security. Indeed, one study of China's cyber warfare and online exploitation capabilities finds that the country's attacks are hardly state of the art.

"China is condemned to inferiority in [information warfare] capabilities for probably several decades," according to "China's Cyber Warfare Capabilities," published in the most recent issue of Security Challenges.

The report's author, Desmond Ball, is a professor in the Strategic and Defense Studies Center at the Australian National University, and has long studied China's cyber warfare and espionage capabilities. He's found that without exception, Chinese attackers rely on rudimentary viruses and Trojan applications that would pale in comparison to the best botnet toolkits available on the black market.

"They have evinced little proficiency with more sophisticated hacking techniques," said Ball in this report, referring to China. "The viruses and Trojan Horses they have used have been fairly easy to detect and remove before any damage has been done or data stolen.

"There is no evidence that China's cyber-warriors can penetrate highly secure networks or covertly steal or falsify critical data," he said. "They would be unable to systematically cripple selected command and control, air defense and intelligence networks and databases of advanced adversaries, or to conduct deception operations by secretly manipulating the data in these networks."

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
SirPubert
50%
50%
SirPubert,
User Rank: Apprentice
11/4/2011 | 5:43:47 AM
re: Feds Cite Chinese Cyber Army Capability
State sponsored hacking should incur sanctions. The greatest gift we have in our country are our programmers. The world at large has no right to sensitive information and it should be protected with physical operants.
Bprince
50%
50%
Bprince,
User Rank: Ninja
11/3/2011 | 8:47:47 PM
re: Feds Cite Chinese Cyber Army Capability
Ball's assessment certainly seems to fly in the face of conventional wisdom. Either way, I think it should be noted that hacks do not necessarily need to be extremely complex to work.
Brian Prince, InformationWeek/Dark Reading Comment Moderator
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-5084
Published: 2015-08-02
The Siemens SIMATIC WinCC Sm@rtClient and Sm@rtClient Lite applications before 01.00.01.00 for Android do not properly store passwords, which allows physically approximate attackers to obtain sensitive information via unspecified vectors.

CVE-2015-5352
Published: 2015-08-02
The x11_open_helper function in channels.c in ssh in OpenSSH before 6.9, when ForwardX11Trusted mode is not used, lacks a check of the refusal deadline for X connections, which makes it easier for remote attackers to bypass intended access restrictions via a connection outside of the permitted time ...

CVE-2015-5537
Published: 2015-08-02
The SSL layer of the HTTPS service in Siemens RuggedCom ROS before 4.2.0 and ROX II does not properly implement CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a different vulnerability than CVE-2014-3566.

CVE-2015-5600
Published: 2015-08-02
The kbdint_next_device function in auth2-chall.c in sshd in OpenSSH through 6.9 does not properly restrict the processing of keyboard-interactive devices within a single connection, which makes it easier for remote attackers to conduct brute-force attacks or cause a denial of service (CPU consumptio...

CVE-2015-1009
Published: 2015-07-31
Schneider Electric InduSoft Web Studio before 7.1.3.5 Patch 5 and Wonderware InTouch Machine Edition through 7.1 SP3 Patch 4 use cleartext for project-window password storage, which allows local users to obtain sensitive information by reading a file.

Dark Reading Radio
Archived Dark Reading Radio
What’s the future of the venerable firewall? We’ve invited two security industry leaders to make their case: Join us and bring your questions and opinions!