Risk
2/4/2010
02:16 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Google Enlists NSA To Defend Its Data

The company is reportedly pursuing a partnership with the National Security Agency to strengthen its network security.

After being hit by a cyber attack from China late last year, Google is reportedly seeking guidance on cyber security from the preeminent electronic intelligence agency in the U.S., the National Security Agency (NSA).

Google and the NSA are said to be hammering out an agreement to allow NSA experts to assist in the investigation of the cyber attack, according to The Washington Post. The negotiation aims to define the ways in which Google can share relevant network security information without violating privacy laws or Google policies.

Google declined to comment.

While Google's involvement with the NSA is sure to raise privacy questions, in part due to the NSA's controversial involvement with warrantless surveillance inside the U.S., security experts dismiss such concerns.

Fears that the Google will hand its servers over to the NSA are "completely unrealistic," stresses Alan Paller, director of research at the SANS Institute. The NSA is an effective partner for the private sector companies because it has the highest level of in-house cyber-security expertise, he says. Other agencies tend to rely more on outside contractors, raising the risk of disclosure of corporate secrets.

The NSA, said Paller, "is very good at keeping secrets."

The NSA did not respond to a request for comment.

The NSA may be best known for its Signals Intelligence mission, to gather foreign signal intelligence, but it also pursues an Information Assurance mission, to keep U.S. networks -- both government and private sector -- secure.

On Tuesday, Dennis C. Blair, Director of National Intelligence told the Senate Intelligence Committee that U.S. critical infrastructure is "severely threatened" by cyber attacks and called the cyber attack on Google "a wake-up call to those who have not taken this problem seriously."

Blair called for cooperation between the government and private sector to mitigate security risks. He said he wanted "to stress that, acting independently, neither the U.S. Government nor the private sector can fully control or protect the country's information infrastructure."

Blair also called for cybersecurity funding, and it appears that legislators have responded: The U.S. House of Representatives just passed the Cybersecurity Enhancement Act of 2009 (HR 4061), which authorizes the National Science Foundation to provide up to $396 million in cybersecurity research grants over the next four years and $94 million in scholarships.

Update: After this story was filed, an NSA spokesperson said in an e-mail, "NSA is not able to comment on specific relationships we may or may not have with U.S. companies. We can say as a general matter, however, that as part of its longstanding Information Assurance (IA) Mission, NSA works with a broad range of commercial partners and research associates to ensure the availability of secure tailored solutions for DoD and national security systems customers today and cutting-edge technologies that will secure the information systems of tomorrow."

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, September 16, 2014
Malicious software is morphing to be more targeted, stealthy, and destructive. Are you prepared to stop it?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-1032
Published: 2014-09-17
Cross-site scripting (XSS) vulnerability in the Euroling SiteSeeker module 3.x before 3.4.5 for EPiServer allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party inf...

CVE-2012-1417
Published: 2014-09-17
Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow remote authenticated users to inject arbitrary web script or HTML via the user field to cgi-bin/ConfigManApp.com.

CVE-2012-1506
Published: 2014-09-17
SQL injection vulnerability in the updateStatus function in lib/models/benefits/Hsp.php in OrangeHRM before 2.7 allows remote authenticated users to execute arbitrary SQL commands via the hspSummaryId parameter to plugins/ajaxCalls/haltResumeHsp.php. NOTE: some of these details are obtained from th...

CVE-2012-1507
Published: 2014-09-17
Multiple cross-site scripting (XSS) vulnerabilities in OrangeHRM before 2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) newHspStatus parameter to plugins/ajaxCalls/haltResumeHsp.php, (2) sortOrder1 parameter to templates/hrfunct/emppop.php, or (3) uri parameter to index...

CVE-2012-2583
Published: 2014-09-17
Cross-site scripting (XSS) vulnerability in Mini Mail Dashboard Widget plugin 1.42 for WordPress allows remote attackers to inject arbitrary web script or HTML via the body of an email.

Best of the Web
Dark Reading Radio