Risk
3/27/2012
03:12 PM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

NSA Chief: China Behind RSA Attacks

Chinese steal a "great deal" of military-related intellectual property, and were responsible for last year's attacks on cybersecurity company RSA, Gen. Keith Alexander tells Senators.

Inside DHS' Classified Cyber-Coordination Headquarters
(click image for larger view)
Slideshow: Inside DHS' Classified Cyber-Coordination Headquarters
China is stealing a "great deal" of military-related intellectual property from the United States and was responsible for last year's attacks against cybersecurity company RSA, U.S. Cyber Command commander and National Security Agency director Gen. Keith Alexander told the Senate Armed Services Committee on Tuesday.

"I can't go into the specifics here, but we do see [thefts] from defense industrial base companies," Alexander said, declining to go into details about other attacks. "There are some very public [attacks], though. The most recent one was the RSA exploits." RSA had earlier pinned the attacks on a "nation state."

The attack against RSA, in which the attacker conducted a spearphishing campaign that sent disguised emails containing malware that installed backdoors via a zero-day Adobe Flash exploit, indicates a high level of sophistication by China's hackers, according to Alexander. "The ability to do it against a company like RSA is such a high-order capability that, if they can do it against RSA, that makes other companies vulnerable," he said.

[ For more background, see Cyber Attacks Becoming Top Terror Threat, FBI Says. ]

Alexander admitted that the government needs to do a better job against these attacks. "We need to make it more difficult for the Chinese to do what they're doing," he said. "Intellectual property isn't well protected, and we can do a better job at protecting it."

Sen. Carl Levin cited, as an example, a Carnegie Mellon University study indicating that a Department of Defense pilot program to share malware signatures with defense contractors has not provided companies with a large amount of information not already known to them.

The NSA director admitted that the government needed more real-time capabilities to work with private sector organizations to stop cyber attacks, and perhaps more authority to take action. He cited an attack in which an "adversary" was attempting to exfiltrate 3 gigabytes of data from a defense contractor in a foreign country, and DOD processes for communicating with that company were too manual.

"I think that industry should have the ability to see these attacks and share them with us in real time," he said. "It's like neighborhood watch. Somebody is breaking into a bank, and somebody needs to be in touch with the police to stop it."

Alexander defended the pilot project, saying that the report and assessment were done early on in the project, and noted that the pilot has continued to expand. "Industry has a bunch of signatures, government has those too," he said. "All of us need to work together to provide the best set of signatures." In fact, Alexander said that he supported mandatory reporting of attacks on critical infrastructure in some cases.

Cyber Command continues to build out its capabilities. For example, Alexander noted that the military is establishing branch offices of Cyber Command at each of the different geographical and functional Combatant Commands in order to provide technical expertise and capabilities and integrate those capabilities into planning for the different Combatant Commands. Within recent weeks, the military conducted a major cyber exercise at Nellis Air Force base.

As federal agencies embrace devices and apps to meet employee demand, the White House seeks one comprehensive mobile strategy. Also in the new Going Mobile issue of InformationWeek Government: Find out how the National Security Agency is developing technologies to make commercial devices suitable for intelligence work. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
Andrew Hornback
50%
50%
Andrew Hornback,
User Rank: Apprentice
3/29/2012 | 1:55:50 AM
re: NSA Chief: China Behind RSA Attacks
Notice the form of attack here against RSA... spearphishing, a Social Engineering problem.

As long as there's a human being involved, even the most infalliable security system will fail. Sure, it's a highly sophisticated attack vector, but how does something like that get stopped? Have to keep everything continually updated and stay vigilant.

I also think it's a very smart idea for the military to include Cyber Command in each of the combatant commands - the world has changed, warfare has changed, we need to be ready for it.

Andrew Hornback
InformationWeek Contributor
techsecurity
50%
50%
techsecurity,
User Rank: Apprentice
3/29/2012 | 5:35:38 PM
re: NSA Chief: China Behind RSA Attacks
"...updated and stay vigilant" can't be done, in this context. It's a vastly harder problem than the unsolved problems with software and network security.

If someone can afford the resources to spend multiple staff-weeks executing a spearphish attack, delivering a newly purchased zero-day exploit, the most vigilant user will fall. Even if you were perfectly vigilant, living in a wire-mesh Faraday cage without electricity and subsisting on sunlight, there is someone in your enterprise with administrative access, who in turn has a naive friend. The friend passes the exploit to the administrator, and "all your accounts are belong to them."

This is a national and international policy problem which is not amenable to lesser means. Few enough people are losing their jobs (none of them policy-makers) that nothing is likely to be done as long as this remains "a cancer and not a heart-attack." For those involved, it will remain profitable, career-enhancing, and "fun" until somebody in the US gets seriously hurt, in way that isn't happening. Meantime, the occasional warning falls on uninterested ears.
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-0914
Published: 2014-07-30
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8 and 6.x and 7.x through 7.5.0.6, Maximo Asset Management 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk, and Maximo Asset Management 6.2 through 6.2.8 for Tivoli IT Asset Management f...

CVE-2014-0915
Published: 2014-07-30
Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo Asset Management 6.2 through 6.2.8, 6.x and 7.1 through 7.1.1.2, and 7.5 through 7.5.0.6; Maximo Asset Management 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk; and Maximo Asset Management 6.2 through 6.2.8...

CVE-2014-0947
Published: 2014-07-30
Unspecified vulnerability in the server in IBM Rational Software Architect Design Manager 4.0.6 allows remote authenticated users to execute arbitrary code via a crafted update site.

CVE-2014-0948
Published: 2014-07-30
Unspecified vulnerability in IBM Rational Software Architect Design Manager and Rational Rhapsody Design Manager 3.x and 4.x before 4.0.7 allows remote authenticated users to execute arbitrary code via a crafted ZIP archive.

CVE-2014-3025
Published: 2014-07-30
Multiple cross-site scripting (XSS) vulnerabilities in IBM Maximo Asset Management 6.2 through 6.2.8, 6.x and 7.1 through 7.1.1.2, and 7.5 through 7.5.0.6; Maximo Asset Management 7.5 through 7.5.0.3 and 7.5.1 through 7.5.1.2 for SmartCloud Control Desk; and Maximo Asset Management 6.2 through 6.2.8...

Best of the Web
Dark Reading Radio