Risk
10/23/2009
07:25 PM
George V. Hulme
George V. Hulme
Commentary
Connect Directly
RSS
E-Mail
50%
50%

Application Security Is National Security

Hacks targeting U.S. government computers are coming from China. We knew that. The Chinese hackers are relying on zero-day software vulnerabilities to exploit critical systems. So, tell me again: why aren't we doing more to require applications be built secure from the start?

Hacks targeting U.S. government computers are coming from China. We knew that. The Chinese hackers are relying on zero-day software vulnerabilities to exploit critical systems. So, tell me again: why aren't we doing more to require applications be built secure from the start?This is an excerpt from the report, Capability of the People's Republic of China to Conduct Cyber Warfare and Computer Network Exploitation [.pdf]:

China is likely using its maturing computer network exploitation capability to support intelligence collection against the US Government and industry by conducting a long term, sophisticated, computer network exploitation campaign. The problem is characterized by disciplined, standardized operations, sophisticated techniques, access to high-end software development resources, a deep knowledge of the targeted networks, and an ability to sustain activities inside targeted networks, sometimes over a period of months.

Analysis of these intrusions is yielding increasing evidence that the intruders are turning to Chinese "black hat" programmers (i.e. individuals who support illegal hacking activities) for customized tools that exploit vulnerabilities in software that vendors have not yet discovered. This type of attack is known as a "zero day exploit" (or "0-day") as the defenders haven't yet started counting the days since the release of vulnerability information. Although these relationships do not prove any government affiliation, it suggests that the individuals participating in ongoing penetrations of US networks have Chinese language skills and have well established ties with the Chinese underground hacker community. Alternately, it may imply that he individuals targeting US networks have access to a well resourced infrastructure that is able to broker these relationships with the Chinese blackhat hacker community and provide tool development support often while an operation is underway.

More clearly: our adversaries (not just criminally motivated Black Hats, but state-sponsored adversaries) are using the fact that most software shipped today is both shoddily designed and insecure to steal billions of intellectual property and state security secrets every year.

The report provided a case study of on infiltration on an unnamed U.S. business. The attack was made possible by a flaw in Adobe Acrobat. And the attack was initiated in the typical way: an e-mail with a maliciously crafted attachment that, once clicked, executes the attack on some software vulnerability and a Trojan horse, botnet, or keystroke logger is injected into the user's system.

These attacks happen in a split second, and anyone can fall victim -- especially when these e-mails come from someone who knows the plenty about the person or organization being targeted. And they're made possible because the PDF viewers, word processors, spreadsheets, Internet browsers, Web applications -- are all -- to some degree vulnerable to attack.

Unfortunately, it's you -- the end user or the organization -- who always suffers the consequences of the vulnerability: not the software developer. Sure, they'll have to endure the cost of developing a patch for a discovered vulnerability: but they're not held liable for your having lost $20 million is research and development on that fancy new widget. Nor are they held liable when a foreign government accesses military secrets.

Perhaps it's time part of the risk for developing insecure software shifts onto software developers. End users have businesses have been shouldering the risk, and the cost, for far too long.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, September 16, 2014
Malicious software is morphing to be more targeted, stealthy, and destructive. Are you prepared to stop it?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2006-1318
Published: 2014-09-19
Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, Office 2004 for Mac, and Office X for Mac do not properly parse record lengths, which allows remote attackers to execute arbitrary code via a malformed control in an Office document, aka "Microsoft Office Control Vulnerability."

CVE-2012-2588
Published: 2014-09-19
Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Enterprise 6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, or (3) Subject header or (4) body in an SMTP e-mail message.

CVE-2012-6659
Published: 2014-09-19
Cross-site scripting (XSS) vulnerability in the admin interface in Phorum before 5.2.19 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVE-2014-1391
Published: 2014-09-19
QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with RLE encoding.

CVE-2014-3614
Published: 2014-09-19
Unspecified vulnerability in PowerDNS Recursor (aka pdns_recursor) 3.6.x before 3.6.1 allows remote attackers to cause a denial of service (crash) via an unknown sequence of malformed packets.

Best of the Web
Dark Reading Radio