Vulnerabilities / Threats
7/1/2013
08:21 PM
Tom Parker
Tom Parker
Products and Releases
50%
50%

Advanced Threats, Imagination, And Perception

Why some industries are staring down the barrel, but still don't know it, putting others at risk

It's no secret that the tech, defense industrial base, and a select few other industries (which we'll call tier-one targets) have been heavily targeted by advanced threat actors in recent years. However, a group of less discussed or publicized industries exists that have found themselves subjected to targeted, often sophisticated attacks. They are creating exposure for many of their clients and are only left with one question: Why us? I'm often asked by business executives from this collective to help characterize why they are now under the microscope of an adversary from a nation where they have no business or competitors; they don't have source code, industrial research, or other intellectual property to steal, and their finances pale in comparison to those of their adversary.

So what gives?

The press has done an imperfect, but reasonable job of educating the masses as to what lurks in the digital shadows of the interwebs, particularly of late -- with some great investigative journalism being authored by the likes of Michael Gross and other media notables, who have gone to significant lengths to understand and articulate the issues in a way that the non-tinfoil hat wearing population can easily understand. Unfortunately, a heavy focus on the common denominator has seemingly created many a preconceived notion that if you're not a defense contractor, you're unlikely a target. Bzzzzzt.

If you're a member of the security industry, the chances are (generalizing here) that you spend most of your life working with financial institutions, insurers, tech companies, state and federal governments, and perhaps a smattering of the odd healthcare provider and the odd companies here and there. This is largely an issue of perception, and it's causing a growing number of organizations to get caught in a crossfire that they never saw coming. Nine out of 10 times, in cases where research, defense/military data, or other intellectual property are not the motivating factor, it's about one thing: your rolodex. Here in DC, a growing number of trade associations, NGOs, PR, law firms, and lobbying shops are falling victim to an adversary who has no long term interest in them, but views them as an excellent opportunity to gather intelligence on future targets.

Unfortunately, as it relates to the cybersecurity domain, many of these industries have been sleeping under a rock for the past decade, and, as such, are ill-equipped to detect, defend, and respond to the handy work of our friends across the ocean.

The adversary will always take a path of least resistance. As such, a lack of awareness of the threat and preparedness to handle it on the part of industries falling into this grouping also creates a significant challenge for the tier one targets, which are likely doing business with many of them and are themselves far too occupied with fending off direct attacks to be concerned about the security of their PR firms' (who, by the way, are also handling PR around data breaches for them!) email servers.

Nonwithstanding those who have had a rude awakening via a data breach, more often than not, a direct conversation with many such organizations will go nowhere, and so it's really on the tier one targets to consider and enter into a dialogue with those they are engaged with on an ongoing basis and might fall into the unwashed category. While right-to-audit/pen test/assess clauses in service provider contracts are great, they are only ever generally applied when significant, obvious data sharing (such as a cloud provider or ISP) is involved and for the purpose of this conversation aren't worth the paper they are written on.

In closing, good defense today isn't just about contemplating how the adversary might come after you directly, but understanding how the adversary may move sideways to attack you once a direct approach has become too costly.

Organizations that are nonobvious targets need to think hard about their own attack profile and the ways in which they might be putting at risk their more high-profile, more frequently targeted clients due to miss-guided preconceived notions of adversary behavior and a failure of imagination with regard to what the future may hold.

Tom Parker is CTO at FusionX

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
ophilino
50%
50%
ophilino,
User Rank: Apprentice
1/8/2014 | 9:47:52 PM
re: Advanced Threats, Imagination, And Perception
Great insights - I would characterize it as the ostrich syndrome: they would just rather ignore it or as the ostrich does, bury his head in the sand when confronted by danger hoping it will go away
MarciaNWC
50%
50%
MarciaNWC,
User Rank: Apprentice
7/8/2013 | 3:58:56 PM
re: Advanced Threats, Imagination, And Perception
Seems that regulatory requirements should be leading more organizations to pay attention to business partner/contractor security.
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5427
Published: 2015-03-29
Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to read pa...

CVE-2014-5428
Published: 2015-03-29
Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integratio...

CVE-2014-9205
Published: 2015-03-29
Stack-based buffer overflow in the PmBase64Decode function in an unspecified demonstration application in MICROSYS PROMOTIC stable before 8.2.19 and PROMOTIC development before 8.3.2 allows remote attackers to execute arbitrary code by providing a large amount of data.

CVE-2015-0528
Published: 2015-03-29
The RPC daemon in EMC Isilon OneFS 6.5.x and 7.0.x before 7.0.2.13, 7.1.0 before 7.1.0.6, 7.1.1 before 7.1.1.2, and 7.2.0 before 7.2.0.1 allows local users to gain privileges by leveraging an ability to modify system files.

CVE-2015-0996
Published: 2015-03-29
Schneider Electric InduSoft Web Studio before 7.1.3.4 SP3 Patch 4 and InTouch Machine Edition 2014 before 7.1.3.4 SP3 Patch 4 rely on a hardcoded cleartext password to control read access to Project files and Project Configuration files, which makes it easier for local users to obtain sensitive info...

Dark Reading Radio
Archived Dark Reading Radio
Good hackers--aka security researchers--are worried about the possible legal and professional ramifications of President Obama's new proposed crackdown on cyber criminals.