Risk
3/21/2013
01:09 PM
50%
50%

NASA Tightens Security In Response To Insider Threat

NASA shuts down database and tightens restrictions on remote access following the arrest of a Chinese contractor on suspicion of intellectual property theft.

Military Drones Present And Future: Visual Tour
Military Drones Present And Future: Visual Tour
(click image for larger view and for slideshow)
NASA has closed down its technical reports database and imposed tighter restrictions on remote access to its computer systems following the arrest of a Chinese contractor on suspicion of intellectual property theft.

NASA administrator Charles Bolden outlined those and other security measures in March 20 testimony before a congressional subcommittee. Bolden said he had ordered a review of the access that foreign nationals from designated countries -- including China, Iran and North Korea -- are given to NASA facilities and a moratorium on providing new access to citizens of those countries.

The agency's actions follow the March 16 arrest of Bo Jiang, a Chinese citizen, at Dulles Airport in Washington, D.C., as he prepared to leave the United States. The FBI, in its application for an arrest warrant, said it was investigating violations of the Arms Export Control Act.

[ NASA has suffered other security breaches in recent months. Read Stolen NASA Laptop Had Unencrypted Employee Data. ]

Jiang worked as a contractor with the National Institute of Aerospace, a nonprofit research organization, at NASA's Langley Research Center. During a border stop at Dulles, Jiang allegedly said that he had in his possession a cellphone, memory stick, external hard drive and new computer. During a subsequent search of Jiang's possessions, the agents found a second laptop, hard drive and SIM card, according to the arrest warrant.

Jiang was arraigned March 19 in federal district court in Norfolk, Va., on a charge of lying to federal agents. The contents of the confiscated electronic media have not been revealed.

Rep. Frank Wolf (R-Va.), chairman of the House appropriations subcommittee that funds the space agency, said in a press conference that whistleblowers at NASA prompted the investigation. Wolf said Jiang was working on high-tech imaging technology that could be of potential interest to the Chinese military. Citing the arrest warrant, Wolf said Jiang had previously traveled to China with a NASA laptop "that agents believe to have contained sensitive information."

Wolf accused NASA of circumventing restrictions on the hiring of foreign nationals and said he had evidence that the NIA might employ other Chinese nationals under similar arrangements. The congressman called on NASA to audit all of its contractors that employ citizens of countries or organizations considered "entities of concern."

Wolf, in his seventeenth year in Congress, has been focused on the threat of Chinese cyber espionage. Earlier this month, he warned of security threats and the potential leak of classified information at NASA's Ames Research Center, and he pointed to the Chinese government's "systematic and aggressive efforts to steal" sensitive technology.

A well-defended perimeter is only half the battle in securing the government's IT environments. Agencies must also protect their most valuable data. Also in the new, all-digital Secure The Data Center issue of InformationWeek Government: The White House's gun control efforts are at risk of failure because the Bureau of Alcohol, Tobacco, Firearms and Explosives' outdated Firearms Tracing System is in need of an upgrade. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
PJS880
50%
50%
PJS880,
User Rank: Ninja
4/2/2013 | 3:03:58 PM
re: NASA Tightens Security In Response To Insider Threat
Any system administrator will tell you that having remote access to people is usually a bad idea if security measure is not taken for remote access. Good catch though, to bad they do not know what he already transported to China and what information was on it. There is an obvious issue here working with national, not saying eliminate them, just have tighter security measures imposed and deeper detailed background reports. I wonder what will become of this guy, do we have the authority to detain and convict him?

Paul Sprague
InformationWeek Contributor
moarsauce123
50%
50%
moarsauce123,
User Rank: Apprentice
3/22/2013 | 5:36:31 PM
re: NASA Tightens Security In Response To Insider Threat
Keep hiring Chinese nationals for sensitive stuff, you idiots!
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-9710
Published: 2015-05-27
The Btrfs implementation in the Linux kernel before 3.19 does not ensure that the visible xattr state is consistent with a requested replacement, which allows local users to bypass intended ACL settings and gain privileges via standard filesystem operations (1) during an xattr-replacement time windo...

CVE-2014-9715
Published: 2015-05-27
include/net/netfilter/nf_conntrack_extend.h in the netfilter subsystem in the Linux kernel before 3.14.5 uses an insufficiently large data type for certain extension data, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via outbound network traffic that trig...

CVE-2015-2666
Published: 2015-05-27
Stack-based buffer overflow in the get_matching_model_microcode function in arch/x86/kernel/cpu/microcode/intel_early.c in the Linux kernel before 4.0 allows context-dependent attackers to gain privileges by constructing a crafted microcode header and leveraging root privileges for write access to t...

CVE-2015-2830
Published: 2015-05-27
arch/x86/kernel/entry_64.S in the Linux kernel before 3.19.2 does not prevent the TS_COMPAT flag from reaching a user-mode task, which might allow local users to bypass the seccomp or audit protection mechanism via a crafted application that uses the (1) fork or (2) close system call, as demonstrate...

CVE-2015-2922
Published: 2015-05-27
The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message.

Dark Reading Radio
Archived Dark Reading Radio
Join security and risk expert John Pironti and Dark Reading Editor-in-Chief Tim Wilson for a live online discussion of the sea-changing shift in security strategy and the many ways it is affecting IT and business.