Government // Cybersecurity
3/5/2010
07:55 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

FBI Director Promises Privacy, Information About Attacks To Breach Victim Organizations

Robert Mueller tells attendees FBI 'cannot act' if businesses don't report cyberattacks

SAN FRANCISCO -- RSA Conference 2010 -- Organizations are typically hesitant to disclose cyberattacks to the FBI, and their disclosure is "the exception, not the rule," FBI director Robert Mueller told attendees here today in a keynote address.

Mueller said the bureau understands organizations' concerns about privacy and image when it comes to deciding whether to report a cyberattack to the authorities, but promised the FBI would provide more information-sharing and protection of victim organizations' privacy.

"We do not want you to feel victimized a second time by an investigation. And we know that putting on raid jackets, courting the media, and shutting down your systems is not the best way to get the job done," he said. "We will minimize the disruption to your business. We will safeguard your privacy and your data. Where necessary, we will seek protective orders to preserve trade secrets and business confidentiality. And we will share with you what we can, as quickly as we can, about the means and methods of attack."

Mueller cited a recent partnership between the financial industry and the FBI to put together an intelligence report on threats in banking transactions. "We shared that report with more than 4,000 partners. Together we worked to limit the breadth and scope of this potential threat, and we closed the door to countless hackers," Mueller said. He did not provide any details on the threats or the report.

Meanwhile, the threat of cyberterrorism is "real and rapidly expanding," Mueller said. "To date, terrorists have not used the Internet to launch a full-scale cyberattack. But they have executed numerous denial-of-service attacks. And they have defaced numerous Websites, including Congress' Website following President Obama's State of the Union speech," he said, referring to the so-called Iranian Cyber Army hacking group.

"We in the FBI, with our partners in the intelligence community, believe the cyber terrorism threat is real, and it is rapidly expanding. Terrorists have shown a clear interest in pursuing hacking skills. And they will either train their own recruits or hire outsiders, with an eye toward combining physical attacks with cyberattacks."

Targeted attacks for intelligence and espionage are also a major threat, according to Mueller. He noted that intelligence-gathering efforts by hackers to grab "seemingly innocuous" data about a company can provide them a foot in the door into the company's network.

These targeted attacks have resulted in the loss and corruption of victims' data. "We are concerned with the integrity of your source code. If hackers made subtle, undetected changes to your code, they would have a permanent window into everything you do," he said.

The FBI and other law enforcement officials are currently reverse-engineering botnets with plans to knock them offline: Most recently, the collaborative effort resulted in the takedown of the Mariposa botnet.

Mueller said the FBI has special agents "embedded" with law enforcement in Romania, Estonia, and other countries to help coordinate cybercrime investigations. "Together we are making progress. Last October we worked with Egyptian authorities to dismantle a computer-intrusion and money-laundering scheme operating in the United States and Egypt," he said.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message. Kelly Jackson Higgins is Senior Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise Magazine, ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
DevOps’ Impact on Application Security
DevOps’ Impact on Application Security
Managing the interdependency between software and infrastructure is a thorny challenge. Often, it’s a “developers are from Mars, systems engineers are from Venus” situation.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-4734
Published: 2014-07-21
Cross-site scripting (XSS) vulnerability in e107_admin/db.php in e107 2.0 alpha2 and earlier allows remote attackers to inject arbitrary web script or HTML via the type parameter.

CVE-2014-4960
Published: 2014-07-21
Multiple SQL injection vulnerabilities in models\gallery.php in Youtube Gallery (com_youtubegallery) component 4.x through 4.1.7, and possibly 3.x, for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) listid or (2) themeid parameter to index.php.

CVE-2014-5016
Published: 2014-07-21
Multiple cross-site scripting (XSS) vulnerabilities in LimeSurvey 2.05+ Build 140618 allow remote attackers to inject arbitrary web script or HTML via (1) the pid attribute to the getAttribute_json function to application/controllers/admin/participantsaction.php in CPDB, (2) the sa parameter to appl...

CVE-2014-5017
Published: 2014-07-21
SQL injection vulnerability in CPDB in application/controllers/admin/participantsaction.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to execute arbitrary SQL commands via the sidx parameter in a JSON request to admin/participants/sa/getParticipants_json, related to a search parameter...

CVE-2014-5018
Published: 2014-07-21
Incomplete blacklist vulnerability in the autoEscape function in common_helper.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to conduct cross-site scripting (XSS) attacks via the GBK charset in the loadname parameter to index.php, related to the survey resume.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Where do information security startups come from? More important, how can I tell a good one from a flash in the pan? Learn how to separate ITSec wheat from chaff in this episode.