Risk
2/4/2010
02:16 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Google Enlists NSA To Defend Its Data

The company is reportedly pursuing a partnership with the National Security Agency to strengthen its network security.

After being hit by a cyber attack from China late last year, Google is reportedly seeking guidance on cyber security from the preeminent electronic intelligence agency in the U.S., the National Security Agency (NSA).

Google and the NSA are said to be hammering out an agreement to allow NSA experts to assist in the investigation of the cyber attack, according to The Washington Post. The negotiation aims to define the ways in which Google can share relevant network security information without violating privacy laws or Google policies.

Google declined to comment.

While Google's involvement with the NSA is sure to raise privacy questions, in part due to the NSA's controversial involvement with warrantless surveillance inside the U.S., security experts dismiss such concerns.

Fears that the Google will hand its servers over to the NSA are "completely unrealistic," stresses Alan Paller, director of research at the SANS Institute. The NSA is an effective partner for the private sector companies because it has the highest level of in-house cyber-security expertise, he says. Other agencies tend to rely more on outside contractors, raising the risk of disclosure of corporate secrets.

The NSA, said Paller, "is very good at keeping secrets."

The NSA did not respond to a request for comment.

The NSA may be best known for its Signals Intelligence mission, to gather foreign signal intelligence, but it also pursues an Information Assurance mission, to keep U.S. networks -- both government and private sector -- secure.

On Tuesday, Dennis C. Blair, Director of National Intelligence told the Senate Intelligence Committee that U.S. critical infrastructure is "severely threatened" by cyber attacks and called the cyber attack on Google "a wake-up call to those who have not taken this problem seriously."

Blair called for cooperation between the government and private sector to mitigate security risks. He said he wanted "to stress that, acting independently, neither the U.S. Government nor the private sector can fully control or protect the country's information infrastructure."

Blair also called for cybersecurity funding, and it appears that legislators have responded: The U.S. House of Representatives just passed the Cybersecurity Enhancement Act of 2009 (HR 4061), which authorizes the National Science Foundation to provide up to $396 million in cybersecurity research grants over the next four years and $94 million in scholarships.

Update: After this story was filed, an NSA spokesperson said in an e-mail, "NSA is not able to comment on specific relationships we may or may not have with U.S. companies. We can say as a general matter, however, that as part of its longstanding Information Assurance (IA) Mission, NSA works with a broad range of commercial partners and research associates to ensure the availability of secure tailored solutions for DoD and national security systems customers today and cutting-edge technologies that will secure the information systems of tomorrow."

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-8917
Published: 2015-01-28
Multiple cross-site scripting (XSS) vulnerabilities in (1) dojox/form/resources/uploader.swf (aka upload.swf), (2) dojox/form/resources/fileuploader.swf (aka fileupload.swf), (3) dojox/av/resources/audio.swf, and (4) dojox/av/resources/video.swf in the IBM Dojo Toolkit, as used in IBM Social Media A...

CVE-2014-8920
Published: 2015-01-28
Buffer overflow in the Data Transfer Program in IBM i Access 5770-XE1 5R4, 6.1, and 7.1 on Windows allows local users to gain privileges via unspecified vectors.

CVE-2015-0235
Published: 2015-01-28
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."

CVE-2015-0312
Published: 2015-01-28
Double free vulnerability in Adobe Flash Player before 13.0.0.264 and 14.x through 16.x before 16.0.0.296 on Windows and OS X and before 11.2.202.440 on Linux allows attackers to execute arbitrary code via unspecified vectors.

CVE-2015-0581
Published: 2015-01-28
The XML parser in Cisco Prime Service Catalog before 10.1 allows remote authenticated users to read arbitrary files or cause a denial of service (CPU and memory consumption) via an external entity declaration in conjunction with an entity reference, as demonstrated by reading private keys, related t...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
If youíre a security professional, youíve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.