07:25 PM
George V. Hulme
George V. Hulme

Application Security Is National Security

Hacks targeting U.S. government computers are coming from China. We knew that. The Chinese hackers are relying on zero-day software vulnerabilities to exploit critical systems. So, tell me again: why aren't we doing more to require applications be built secure from the start?

Hacks targeting U.S. government computers are coming from China. We knew that. The Chinese hackers are relying on zero-day software vulnerabilities to exploit critical systems. So, tell me again: why aren't we doing more to require applications be built secure from the start?This is an excerpt from the report, Capability of the People's Republic of China to Conduct Cyber Warfare and Computer Network Exploitation [.pdf]:

China is likely using its maturing computer network exploitation capability to support intelligence collection against the US Government and industry by conducting a long term, sophisticated, computer network exploitation campaign. The problem is characterized by disciplined, standardized operations, sophisticated techniques, access to high-end software development resources, a deep knowledge of the targeted networks, and an ability to sustain activities inside targeted networks, sometimes over a period of months.

Analysis of these intrusions is yielding increasing evidence that the intruders are turning to Chinese "black hat" programmers (i.e. individuals who support illegal hacking activities) for customized tools that exploit vulnerabilities in software that vendors have not yet discovered. This type of attack is known as a "zero day exploit" (or "0-day") as the defenders haven't yet started counting the days since the release of vulnerability information. Although these relationships do not prove any government affiliation, it suggests that the individuals participating in ongoing penetrations of US networks have Chinese language skills and have well established ties with the Chinese underground hacker community. Alternately, it may imply that he individuals targeting US networks have access to a well resourced infrastructure that is able to broker these relationships with the Chinese blackhat hacker community and provide tool development support often while an operation is underway.

More clearly: our adversaries (not just criminally motivated Black Hats, but state-sponsored adversaries) are using the fact that most software shipped today is both shoddily designed and insecure to steal billions of intellectual property and state security secrets every year.

The report provided a case study of on infiltration on an unnamed U.S. business. The attack was made possible by a flaw in Adobe Acrobat. And the attack was initiated in the typical way: an e-mail with a maliciously crafted attachment that, once clicked, executes the attack on some software vulnerability and a Trojan horse, botnet, or keystroke logger is injected into the user's system.

These attacks happen in a split second, and anyone can fall victim -- especially when these e-mails come from someone who knows the plenty about the person or organization being targeted. And they're made possible because the PDF viewers, word processors, spreadsheets, Internet browsers, Web applications -- are all -- to some degree vulnerable to attack.

Unfortunately, it's you -- the end user or the organization -- who always suffers the consequences of the vulnerability: not the software developer. Sure, they'll have to endure the cost of developing a patch for a discovered vulnerability: but they're not held liable for your having lost $20 million is research and development on that fancy new widget. Nor are they held liable when a foreign government accesses military secrets.

Perhaps it's time part of the risk for developing insecure software shifts onto software developers. End users have businesses have been shouldering the risk, and the cost, for far too long.

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Current Issue
Five Emerging Security Threats - And What You Can Learn From Them
At Black Hat USA, researchers unveiled some nasty vulnerabilities. Is your organization ready?
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
Cybercrime has become a well-organized business, complete with job specialization, funding, and online customer service. Dark Reading editors speak to cybercrime experts on the evolution of the cybercrime economy and the nature of today's attackers.