Attacks/Breaches
10/12/2011
12:09 PM
50%
50%

RSA Pins SecurID Attacks On Nation State

Security firm said it traced the attack on its authentication system to two groups working for one nation state, but declined to name the country.

10 Companies Driving Mobile Security
10 Companies Driving Mobile Security
(click image for larger view and for slideshow)
RSA has traced the attack against its network, resulting in the compromise of sensitive information relating to its two-factor SecurID authentication system, to two groups, working for one nation state.

Those findings came to light Tuesday, during a press conference at the RSA Conference Europe 2011 in London. "There were two individual groups from one nation state, one supporting the other. One was very visible and one less so," said Arthur Coviello, the executive chairman of RSA, and executive VP at parent company EMC, reported the Inquirer.

But Coviello stopped short of naming the nation state that RSA suspected might be involved. "We've not attributed it to a particular nation state although we're very confident that with the skill, sophistication, and resources involved, it could only have been a nation state," he said.

[Think your intrusion detection and prevention systems are tight? Think again: Most Businesses Don't Spot Hack Attacks.]

Coviello's assertion seems destined to raise as many questions as it answers. "It seems very odd to me for a company to say that they have determined that a country had attacked them, but to not then name the country," said Graham Cluley, senior technology consultant at Sophos, in a blog post.

Furthermore, despite the seeming prevalence of attacks blamed on China--including the so-called Aurora attacks against Google and others last year, as well as the Shady RAT cyberespionage campaign discovered by McAfee this year, Cluley recommended exercising caution. "Inevitably, people are likely to assume that China might have been involved in the attack--but there's nothing in RSA's statements to either implicate China or to back up the claims that any country was involved."

RSA had previously disclosed that it had traced the breach to an advanced attack involving an Excel spreadsheet, named "2011 Recruitment plan.xls," which was attached to a poorly worded email that had been sent to an employee in its financial department. The breach--the full extent of which RSA has yet to detail publicly--has been an embarrassment for the company, given that it sells security software, hardware, and expertise.

At the press conference Tuesday, RSA Security president Thomas Heiser faced sharp questioning as to whether his company had correctly handled the resulting breach notification and cleanup correctly, reported the Inquirer. Notably, RSA delayed offering replacement SecurID tokens to many of its customers, and only later offered them to businesses that it had determined to be most at risk, including military contractors. For others, it instead offered security monitoring services.

"We got out to our top 500 customers relatively quickly," said Heiser, but interfacing with the others took more time. "The challenge was that we have tens of thousands of customers and a lot of them we deal with indirectly, so we were reliant on our marketing press and partners."

Since the SecurID breach, RSA has been sounding a greater alarm over the threat posed by nation states, and recently gathered a group of CIOs in Washington to discuss ways of combating the advanced exploits they're seeing, which often rely on social engineering attacks.

Likewise, in his keynote opening the RSA conference on Tuesday, Coviello said that the three most dangerous groups now attacking businesses online are cybercriminals seeking information that carries a dollar value, hacktivist groups aiming to embarrass businesses, and nation states. "For nation-sponsored attackers behind advanced persistent threats, it's about stealth and sophistication," he said. "Through social engineering they do intelligence gathering--sometimes months in advance of the attack. They learn which end users in corporations or government agencies possess the assets they want."

While such attacks may not appear to be highly sophisticated, they're nonetheless effective. "The attack may start with rudimentary malware and a variety of tools no different from the other groups, or if necessary with a true zero-day exploit. The real differences in sophistication are the concentration of resources behind the attack and the efficiency with which these adversaries operate after gaining entry," he said.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Bprince
50%
50%
Bprince,
User Rank: Ninja
10/13/2011 | 9:16:59 PM
re: RSA Pins SecurID Attacks On Nation State
I suspect that not naming the country, as someone has already suggested, was likely a business decision. I am curious though to hear more specifics on what makes the company think this has to be a state-sponsored attack, although many governments would have a motive.
Brian Prince, InformationWeek contributor
Dragginbutt
50%
50%
Dragginbutt,
User Rank: Apprentice
10/13/2011 | 10:21:19 AM
re: RSA Pins SecurID Attacks On Nation State
What I find disturbing is that RSA has their CORE business applications tied directly to systems that handle daily internal traffic (Email etc). Seems to me, given the importance of the application and the people it serves, they would have kept the two very much seperated..
Security OBE by arrogance perhaps?.
NoSpin1600
50%
50%
NoSpin1600,
User Rank: Apprentice
10/12/2011 | 5:00:04 PM
re: RSA Pins SecurID Attacks On Nation State
Of course they aren't going to point the finger at China, they probably do business in China and don't want to loose the revenue.
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Five Emerging Security Threats - And What You Can Learn From Them
At Black Hat USA, researchers unveiled some nasty vulnerabilities. Is your organization ready?
Flash Poll
Dark Reading Strategic Security Report: The Impact of Enterprise Data Breaches
Dark Reading Strategic Security Report: The Impact of Enterprise Data Breaches
Social engineering, ransomware, and other sophisticated exploits are leading to new IT security compromises every day. Dark Reading's 2016 Strategic Security Survey polled 300 IT and security professionals to get information on breach incidents, the fallout they caused, and how recent events are shaping preparations for inevitable attacks in the coming year. Download this report to get a look at data from the survey and to find out what a breach might mean for your organization.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
Security researchers are finding that there's a growing market for the vulnerabilities they discover and persistent conundrum as to the right way to disclose them. Dark Reading editors will speak to experts -- Veracode CTO and co-founder Chris Wysopal and HackerOne co-founder and CTO Alex Rice -- about bug bounties and the expanding market for zero-day security vulnerabilities.