02:16 PM
Connect Directly

Google Enlists NSA To Defend Its Data

The company is reportedly pursuing a partnership with the National Security Agency to strengthen its network security.

After being hit by a cyber attack from China late last year, Google is reportedly seeking guidance on cyber security from the preeminent electronic intelligence agency in the U.S., the National Security Agency (NSA).

Google and the NSA are said to be hammering out an agreement to allow NSA experts to assist in the investigation of the cyber attack, according to The Washington Post. The negotiation aims to define the ways in which Google can share relevant network security information without violating privacy laws or Google policies.

Google declined to comment.

While Google's involvement with the NSA is sure to raise privacy questions, in part due to the NSA's controversial involvement with warrantless surveillance inside the U.S., security experts dismiss such concerns.

Fears that the Google will hand its servers over to the NSA are "completely unrealistic," stresses Alan Paller, director of research at the SANS Institute. The NSA is an effective partner for the private sector companies because it has the highest level of in-house cyber-security expertise, he says. Other agencies tend to rely more on outside contractors, raising the risk of disclosure of corporate secrets.

The NSA, said Paller, "is very good at keeping secrets."

The NSA did not respond to a request for comment.

The NSA may be best known for its Signals Intelligence mission, to gather foreign signal intelligence, but it also pursues an Information Assurance mission, to keep U.S. networks -- both government and private sector -- secure.

On Tuesday, Dennis C. Blair, Director of National Intelligence told the Senate Intelligence Committee that U.S. critical infrastructure is "severely threatened" by cyber attacks and called the cyber attack on Google "a wake-up call to those who have not taken this problem seriously."

Blair called for cooperation between the government and private sector to mitigate security risks. He said he wanted "to stress that, acting independently, neither the U.S. Government nor the private sector can fully control or protect the country's information infrastructure."

Blair also called for cybersecurity funding, and it appears that legislators have responded: The U.S. House of Representatives just passed the Cybersecurity Enhancement Act of 2009 (HR 4061), which authorizes the National Science Foundation to provide up to $396 million in cybersecurity research grants over the next four years and $94 million in scholarships.

Update: After this story was filed, an NSA spokesperson said in an e-mail, "NSA is not able to comment on specific relationships we may or may not have with U.S. companies. We can say as a general matter, however, that as part of its longstanding Information Assurance (IA) Mission, NSA works with a broad range of commercial partners and research associates to ensure the availability of secure tailored solutions for DoD and national security systems customers today and cutting-edge technologies that will secure the information systems of tomorrow."

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Current Issue
Dark Reading Tech Digest September 7, 2015
Some security flaws go beyond simple app vulnerabilities. Have you checked for these?
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2015-10-02
Buffer overflow in Canary Labs Trend Web Server before 9.5.2 allows remote attackers to execute arbitrary code via a crafted TCP packet.

Published: 2015-10-02
Cisco NX-OS 6.0(2)U6(0.46) on N3K devices allows remote authenticated users to cause a denial of service (temporary SNMP outage) via an SNMP request for an OID that does not exist, aka Bug ID CSCuw36684.

Published: 2015-10-02
Cisco Email Security Appliance (ESA) 8.5.6-106 and 9.6.0-042 allows remote authenticated users to cause a denial of service (file-descriptor consumption and device reload) via crafted HTTP requests, aka Bug ID CSCuw32211.

Published: 2015-10-01
lxc-start in lxc before 1.0.8 and 1.1.x before 1.1.4 allows local container administrators to escape AppArmor confinement via a symlink attack on a (1) mount target or (2) bind mount source.

Published: 2015-10-01
kernel_crashdump in Apport before 2.19 allows local users to cause a denial of service (disk consumption) or possibly gain privileges via a (1) symlink or (2) hard link attack on /var/crash/vmcore.log.

Dark Reading Radio
Archived Dark Reading Radio
What can the information security industry do to solve the IoT security problem? Learn more and join the conversation on the next episode of Dark Reading Radio.