Risk

3/27/2012
03:12 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

NSA Chief: China Behind RSA Attacks

Chinese steal a "great deal" of military-related intellectual property, and were responsible for last year's attacks on cybersecurity company RSA, Gen. Keith Alexander tells Senators.

Inside DHS' Classified Cyber-Coordination Headquarters
(click image for larger view)
Slideshow: Inside DHS' Classified Cyber-Coordination Headquarters
China is stealing a "great deal" of military-related intellectual property from the United States and was responsible for last year's attacks against cybersecurity company RSA, U.S. Cyber Command commander and National Security Agency director Gen. Keith Alexander told the Senate Armed Services Committee on Tuesday.

"I can't go into the specifics here, but we do see [thefts] from defense industrial base companies," Alexander said, declining to go into details about other attacks. "There are some very public [attacks], though. The most recent one was the RSA exploits." RSA had earlier pinned the attacks on a "nation state."

The attack against RSA, in which the attacker conducted a spearphishing campaign that sent disguised emails containing malware that installed backdoors via a zero-day Adobe Flash exploit, indicates a high level of sophistication by China's hackers, according to Alexander. "The ability to do it against a company like RSA is such a high-order capability that, if they can do it against RSA, that makes other companies vulnerable," he said.

[ For more background, see Cyber Attacks Becoming Top Terror Threat, FBI Says. ]

Alexander admitted that the government needs to do a better job against these attacks. "We need to make it more difficult for the Chinese to do what they're doing," he said. "Intellectual property isn't well protected, and we can do a better job at protecting it."

Sen. Carl Levin cited, as an example, a Carnegie Mellon University study indicating that a Department of Defense pilot program to share malware signatures with defense contractors has not provided companies with a large amount of information not already known to them.

The NSA director admitted that the government needed more real-time capabilities to work with private sector organizations to stop cyber attacks, and perhaps more authority to take action. He cited an attack in which an "adversary" was attempting to exfiltrate 3 gigabytes of data from a defense contractor in a foreign country, and DOD processes for communicating with that company were too manual.

"I think that industry should have the ability to see these attacks and share them with us in real time," he said. "It's like neighborhood watch. Somebody is breaking into a bank, and somebody needs to be in touch with the police to stop it."

Alexander defended the pilot project, saying that the report and assessment were done early on in the project, and noted that the pilot has continued to expand. "Industry has a bunch of signatures, government has those too," he said. "All of us need to work together to provide the best set of signatures." In fact, Alexander said that he supported mandatory reporting of attacks on critical infrastructure in some cases.

Cyber Command continues to build out its capabilities. For example, Alexander noted that the military is establishing branch offices of Cyber Command at each of the different geographical and functional Combatant Commands in order to provide technical expertise and capabilities and integrate those capabilities into planning for the different Combatant Commands. Within recent weeks, the military conducted a major cyber exercise at Nellis Air Force base.

As federal agencies embrace devices and apps to meet employee demand, the White House seeks one comprehensive mobile strategy. Also in the new Going Mobile issue of InformationWeek Government: Find out how the National Security Agency is developing technologies to make commercial devices suitable for intelligence work. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
techsecurity
50%
50%
techsecurity,
User Rank: Apprentice
3/29/2012 | 5:35:38 PM
re: NSA Chief: China Behind RSA Attacks
"...updated and stay vigilant" can't be done, in this context. It's a vastly harder problem than the unsolved problems with software and network security.

If someone can afford the resources to spend multiple staff-weeks executing a spearphish attack, delivering a newly purchased zero-day exploit, the most vigilant user will fall. Even if you were perfectly vigilant, living in a wire-mesh Faraday cage without electricity and subsisting on sunlight, there is someone in your enterprise with administrative access, who in turn has a naive friend. The friend passes the exploit to the administrator, and "all your accounts are belong to them."

This is a national and international policy problem which is not amenable to lesser means. Few enough people are losing their jobs (none of them policy-makers) that nothing is likely to be done as long as this remains "a cancer and not a heart-attack." For those involved, it will remain profitable, career-enhancing, and "fun" until somebody in the US gets seriously hurt, in way that isn't happening. Meantime, the occasional warning falls on uninterested ears.
Andrew Hornback
50%
50%
Andrew Hornback,
User Rank: Apprentice
3/29/2012 | 1:55:50 AM
re: NSA Chief: China Behind RSA Attacks
Notice the form of attack here against RSA... spearphishing, a Social Engineering problem.

As long as there's a human being involved, even the most infalliable security system will fail. Sure, it's a highly sophisticated attack vector, but how does something like that get stopped? Have to keep everything continually updated and stay vigilant.

I also think it's a very smart idea for the military to include Cyber Command in each of the combatant commands - the world has changed, warfare has changed, we need to be ready for it.

Andrew Hornback
InformationWeek Contributor
Is Threat Intelligence Garbage?
Chris McDaniels, Chief Information Security Officer of Mosaic451,  5/23/2018
New Mexico Man Sentenced on DDoS, Gun Charges
Dark Reading Staff 5/18/2018
What Israel's Elite Defense Force Unit 8200 Can Teach Security about Diversity
Lital Asher-Dotan, Senior Director, Security Research and Content, Cybereason,  5/21/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Shhh!  They're watching... And you have a laptop?  
Current Issue
Flash Poll
[Strategic Security Report] Navigating the Threat Intelligence Maze
[Strategic Security Report] Navigating the Threat Intelligence Maze
Most enterprises are using threat intel services, but many are still figuring out how to use the data they're collecting. In this Dark Reading survey we give you a look at what they're doing today - and where they hope to go.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-3018
PUBLISHED: 2018-05-24
The AXIS webapp in deploy-tomcat/axis in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 allows remote attackers to obtain sensitive configuration information via a direct request, as demonstrated by happyaxis.jsp. IBM X-Force ID: 84354.
CVE-2013-3023
PUBLISHED: 2018-05-24
IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 might allow remote attackers to obtain sensitive information about Tomcat credentials by sniffing the network for a session in which HTTP is used. IBM X-Force ID: 84361.
CVE-2013-3024
PUBLISHED: 2018-05-24
IBM WebSphere Application Server (WAS) 8.5 through 8.5.0.2 on UNIX allows local users to gain privileges by leveraging improper process initialization. IBM X-Force ID: 84362.
CVE-2018-5674
PUBLISHED: 2018-05-24
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before 9.1 and PhantomPDF before 9.1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw...
CVE-2018-5675
PUBLISHED: 2018-05-24
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader before 9.1 and PhantomPDF before 9.1. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw...