Attacks/Breaches
11/3/2011
02:10 PM
Connect Directly
RSS
E-Mail
50%
50%

Feds Cite Chinese Cyber Army Capability

U.S. government report blames China and Russia for cyber theft of U.S. economic secrets, but one expert questions China's actual hacking capabilities.

10 Massive Security Breaches
(click image for larger view)
Slideshow: 10 Massive Security Breaches
The U.S. government continues to point the cyber-attack finger at China and Russia, but at least one academic is questioning the actual capabilities of China's cyber army.

The most recent U.S. government accusations came on Thursday, with the release of a report to Congress from the top U.S. counterintelligence agency. The report's title, "Foreign Spies Stealing U.S. Economic Secrets in Cyberspace," left little doubt as to its findings. All that was left was to identify the foreign governments in question.

"Chinese actors are the world's most active and persistent perpetrators of economic espionage," according to the report, released by the Office of the National Counterintelligence Executive. And, "Russia's intelligence services are conducting a range of activities to collect economic information and technology from U.S. targets."

[ How much of a threat are the Chinese? Chinese Military Blamed For Hacking U.S. Satellites. ]

"Trade secrets developed over thousands of working hours by our brightest minds are stolen in a split second and transferred to our competitors," said national counterintelligence executive Robert "Bear" Bryant, at a press briefing that detailed the report's findings, reported The Washington Post.

While the annual counterintelligence report has been released since 1995, this is the first year that a report has emphasized "foreign collectors" exploits. According to news reports, administration officials said that was because of the severity of the problem.

Part of the issue, of course, is that nearly all business-critical information today gets stored digitally, which makes for a larger online attack target than ever before. Unlike the old days of espionage, online attackers also face few personal risks when they try to procure digital data. "Cyberspace makes it possible for foreign collectors to gather enormous quantities of information quickly and with little risk, whether via remote exploitation of victims' computer networks, downloads of data to external media devices, or email messages transmitting sensitive information," according to the report.

But China and Russia aren't the only countries being blamed. In fact, U.S. allies are also gunning for sensitive data, sometimes using social engineering attacks to get it. "Some U.S. allies and partners use their broad access to U.S. institutions to acquire sensitive U.S. economic and technology information, primarily through aggressive elicitation and other human intelligence tactics. Some of these states have advanced cyber capabilities," said the report.

But how bad is the actual threat? In the wake of reports such as this one, observers sometimes accuse the government of inflating cyber threats, in part due to agencies positioning themselves to be the future guardians of the nation's cyber defenses, in light of the potential for massive, related appropriations from Congress.

If China has unleashed a massive intelligence-gathering campaign against the United States and its close allies, however, what can be done about it? For starters, leading government and private sector CIOs have called on the government to improve its threat intelligence information-sharing efforts with the private sector, to help businesses more easily spot advanced persistent threats that can target just a handful of computers at a small number of companies, yet succeed.

Information aside, some of the blame for China's success at spying may go to U.S. businesses simply not being serious enough about information security. Indeed, one study of China's cyber warfare and online exploitation capabilities finds that the country's attacks are hardly state of the art.

"China is condemned to inferiority in [information warfare] capabilities for probably several decades," according to "China's Cyber Warfare Capabilities," published in the most recent issue of Security Challenges.

The report's author, Desmond Ball, is a professor in the Strategic and Defense Studies Center at the Australian National University, and has long studied China's cyber warfare and espionage capabilities. He's found that without exception, Chinese attackers rely on rudimentary viruses and Trojan applications that would pale in comparison to the best botnet toolkits available on the black market.

"They have evinced little proficiency with more sophisticated hacking techniques," said Ball in this report, referring to China. "The viruses and Trojan Horses they have used have been fairly easy to detect and remove before any damage has been done or data stolen.

"There is no evidence that China's cyber-warriors can penetrate highly secure networks or covertly steal or falsify critical data," he said. "They would be unable to systematically cripple selected command and control, air defense and intelligence networks and databases of advanced adversaries, or to conduct deception operations by secretly manipulating the data in these networks."

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
SirPubert
50%
50%
SirPubert,
User Rank: Apprentice
11/4/2011 | 5:43:47 AM
re: Feds Cite Chinese Cyber Army Capability
State sponsored hacking should incur sanctions. The greatest gift we have in our country are our programmers. The world at large has no right to sensitive information and it should be protected with physical operants.
Bprince
50%
50%
Bprince,
User Rank: Ninja
11/3/2011 | 8:47:47 PM
re: Feds Cite Chinese Cyber Army Capability
Ball's assessment certainly seems to fly in the face of conventional wisdom. Either way, I think it should be noted that hacks do not necessarily need to be extremely complex to work.
Brian Prince, InformationWeek/Dark Reading Comment Moderator
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6117
Published: 2014-07-11
Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear log files, and perform other actions via a request to TCP port 37777.

CVE-2014-0174
Published: 2014-07-11
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

CVE-2014-3485
Published: 2014-07-11
The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, allows remote authenticated users to read arbitrary files and have other unspecified impact via unknown vectors, related to an XML External Entity (XXE) issue.

CVE-2014-3499
Published: 2014-07-11
Docker 1.0.0 uses world-readable and world-writable permissions on the management socket, which allows local users to gain privileges via unspecified vectors.

CVE-2014-3503
Published: 2014-07-11
Apache Syncope 1.1.x before 1.1.8 uses weak random values to generate passwords, which makes it easier for remote attackers to guess the password via a brute force attack.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Marilyn Cohodas and her guests look at the evolving nature of the relationship between CIO and CSO.