Risk
3/27/2012
03:12 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

NSA Chief: China Behind RSA Attacks

Chinese steal a "great deal" of military-related intellectual property, and were responsible for last year's attacks on cybersecurity company RSA, Gen. Keith Alexander tells Senators.

Inside DHS' Classified Cyber-Coordination Headquarters
(click image for larger view)
Slideshow: Inside DHS' Classified Cyber-Coordination Headquarters
China is stealing a "great deal" of military-related intellectual property from the United States and was responsible for last year's attacks against cybersecurity company RSA, U.S. Cyber Command commander and National Security Agency director Gen. Keith Alexander told the Senate Armed Services Committee on Tuesday.

"I can't go into the specifics here, but we do see [thefts] from defense industrial base companies," Alexander said, declining to go into details about other attacks. "There are some very public [attacks], though. The most recent one was the RSA exploits." RSA had earlier pinned the attacks on a "nation state."

The attack against RSA, in which the attacker conducted a spearphishing campaign that sent disguised emails containing malware that installed backdoors via a zero-day Adobe Flash exploit, indicates a high level of sophistication by China's hackers, according to Alexander. "The ability to do it against a company like RSA is such a high-order capability that, if they can do it against RSA, that makes other companies vulnerable," he said.

[ For more background, see Cyber Attacks Becoming Top Terror Threat, FBI Says. ]

Alexander admitted that the government needs to do a better job against these attacks. "We need to make it more difficult for the Chinese to do what they're doing," he said. "Intellectual property isn't well protected, and we can do a better job at protecting it."

Sen. Carl Levin cited, as an example, a Carnegie Mellon University study indicating that a Department of Defense pilot program to share malware signatures with defense contractors has not provided companies with a large amount of information not already known to them.

The NSA director admitted that the government needed more real-time capabilities to work with private sector organizations to stop cyber attacks, and perhaps more authority to take action. He cited an attack in which an "adversary" was attempting to exfiltrate 3 gigabytes of data from a defense contractor in a foreign country, and DOD processes for communicating with that company were too manual.

"I think that industry should have the ability to see these attacks and share them with us in real time," he said. "It's like neighborhood watch. Somebody is breaking into a bank, and somebody needs to be in touch with the police to stop it."

Alexander defended the pilot project, saying that the report and assessment were done early on in the project, and noted that the pilot has continued to expand. "Industry has a bunch of signatures, government has those too," he said. "All of us need to work together to provide the best set of signatures." In fact, Alexander said that he supported mandatory reporting of attacks on critical infrastructure in some cases.

Cyber Command continues to build out its capabilities. For example, Alexander noted that the military is establishing branch offices of Cyber Command at each of the different geographical and functional Combatant Commands in order to provide technical expertise and capabilities and integrate those capabilities into planning for the different Combatant Commands. Within recent weeks, the military conducted a major cyber exercise at Nellis Air Force base.

As federal agencies embrace devices and apps to meet employee demand, the White House seeks one comprehensive mobile strategy. Also in the new Going Mobile issue of InformationWeek Government: Find out how the National Security Agency is developing technologies to make commercial devices suitable for intelligence work. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
techsecurity
50%
50%
techsecurity,
User Rank: Apprentice
3/29/2012 | 5:35:38 PM
re: NSA Chief: China Behind RSA Attacks
"...updated and stay vigilant" can't be done, in this context. It's a vastly harder problem than the unsolved problems with software and network security.

If someone can afford the resources to spend multiple staff-weeks executing a spearphish attack, delivering a newly purchased zero-day exploit, the most vigilant user will fall. Even if you were perfectly vigilant, living in a wire-mesh Faraday cage without electricity and subsisting on sunlight, there is someone in your enterprise with administrative access, who in turn has a naive friend. The friend passes the exploit to the administrator, and "all your accounts are belong to them."

This is a national and international policy problem which is not amenable to lesser means. Few enough people are losing their jobs (none of them policy-makers) that nothing is likely to be done as long as this remains "a cancer and not a heart-attack." For those involved, it will remain profitable, career-enhancing, and "fun" until somebody in the US gets seriously hurt, in way that isn't happening. Meantime, the occasional warning falls on uninterested ears.
Andrew Hornback
50%
50%
Andrew Hornback,
User Rank: Apprentice
3/29/2012 | 1:55:50 AM
re: NSA Chief: China Behind RSA Attacks
Notice the form of attack here against RSA... spearphishing, a Social Engineering problem.

As long as there's a human being involved, even the most infalliable security system will fail. Sure, it's a highly sophisticated attack vector, but how does something like that get stopped? Have to keep everything continually updated and stay vigilant.

I also think it's a very smart idea for the military to include Cyber Command in each of the combatant commands - the world has changed, warfare has changed, we need to be ready for it.

Andrew Hornback
InformationWeek Contributor
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-4594
Published: 2014-10-25
The Payment for Webform module 7.x-1.x before 7.x-1.5 for Drupal does not restrict access by anonymous users, which allows remote anonymous users to use the payment of other anonymous users when submitting a form that requires payment.

CVE-2014-0476
Published: 2014-10-25
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute arbitrary code via a Trojan horse executable. NOTE: this is only a vulnerability when /tmp is not mounted with the noexec option.

CVE-2014-1927
Published: 2014-10-25
The shell_quote function in python-gnupg 0.3.5 does not properly quote strings, which allows context-dependent attackers to execute arbitrary code via shell metacharacters in unspecified vectors, as demonstrated using "$(" command-substitution sequences, a different vulnerability than CVE-2014-1928....

CVE-2014-1928
Published: 2014-10-25
The shell_quote function in python-gnupg 0.3.5 does not properly escape characters, which allows context-dependent attackers to execute arbitrary code via shell metacharacters in unspecified vectors, as demonstrated using "\" (backslash) characters to form multi-command sequences, a different vulner...

CVE-2014-1929
Published: 2014-10-25
python-gnupg 0.3.5 and 0.3.6 allows context-dependent attackers to have an unspecified impact via vectors related to "option injection through positional arguments." NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7323.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.