Risk
2/4/2010
02:16 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Google Enlists NSA To Defend Its Data

The company is reportedly pursuing a partnership with the National Security Agency to strengthen its network security.

After being hit by a cyber attack from China late last year, Google is reportedly seeking guidance on cyber security from the preeminent electronic intelligence agency in the U.S., the National Security Agency (NSA).

Google and the NSA are said to be hammering out an agreement to allow NSA experts to assist in the investigation of the cyber attack, according to The Washington Post. The negotiation aims to define the ways in which Google can share relevant network security information without violating privacy laws or Google policies.

Google declined to comment.

While Google's involvement with the NSA is sure to raise privacy questions, in part due to the NSA's controversial involvement with warrantless surveillance inside the U.S., security experts dismiss such concerns.

Fears that the Google will hand its servers over to the NSA are "completely unrealistic," stresses Alan Paller, director of research at the SANS Institute. The NSA is an effective partner for the private sector companies because it has the highest level of in-house cyber-security expertise, he says. Other agencies tend to rely more on outside contractors, raising the risk of disclosure of corporate secrets.

The NSA, said Paller, "is very good at keeping secrets."

The NSA did not respond to a request for comment.

The NSA may be best known for its Signals Intelligence mission, to gather foreign signal intelligence, but it also pursues an Information Assurance mission, to keep U.S. networks -- both government and private sector -- secure.

On Tuesday, Dennis C. Blair, Director of National Intelligence told the Senate Intelligence Committee that U.S. critical infrastructure is "severely threatened" by cyber attacks and called the cyber attack on Google "a wake-up call to those who have not taken this problem seriously."

Blair called for cooperation between the government and private sector to mitigate security risks. He said he wanted "to stress that, acting independently, neither the U.S. Government nor the private sector can fully control or protect the country's information infrastructure."

Blair also called for cybersecurity funding, and it appears that legislators have responded: The U.S. House of Representatives just passed the Cybersecurity Enhancement Act of 2009 (HR 4061), which authorizes the National Science Foundation to provide up to $396 million in cybersecurity research grants over the next four years and $94 million in scholarships.

Update: After this story was filed, an NSA spokesperson said in an e-mail, "NSA is not able to comment on specific relationships we may or may not have with U.S. companies. We can say as a general matter, however, that as part of its longstanding Information Assurance (IA) Mission, NSA works with a broad range of commercial partners and research associates to ensure the availability of secure tailored solutions for DoD and national security systems customers today and cutting-edge technologies that will secure the information systems of tomorrow."

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7421
Published: 2015-03-02
The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a module name in the salg_name field, a different vulnerability than CVE-2014-9644.

CVE-2014-8160
Published: 2015-03-02
net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols, which allows remote attackers to bypass intended access restrictions via packets with disall...

CVE-2014-9644
Published: 2015-03-02
The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as demonstrated by the vfat(aes) expression, a different vulnerability than CVE-201...

CVE-2015-0239
Published: 2015-03-02
The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a denial of service (guest OS crash) by triggering use of a 16-bit code segment for emulation of a SYS...

CVE-2014-8921
Published: 2015-03-01
The IBM Notes Traveler Companion application 1.0 and 1.1 before 201411010515 for Window Phone, as distributed in IBM Notes Traveler 9.0.1, does not properly restrict the number of executions of the automatic configuration option, which makes it easier for remote attackers to capture credentials by c...

Dark Reading Radio
Archived Dark Reading Radio
How can security professionals better engage with their peers, both in person and online? In this Dark Reading Radio show, we will talk to leaders at some of the security industry’s professional organizations about how security pros can get more involved – with their colleagues in the same industry, with their peers in other industries, and with the IT security community as a whole.