Vulnerabilities / Threats
6/14/2013
09:12 AM
Connect Directly
RSS
E-Mail
50%
50%

Bug Data Buys Businesses Intel From U.S. Government

Thousands of businesses are reportedly exchanging information with the government on zero-day vulnerabilities and online threats in return for classified intelligence.

The Syrian Electronic Army: 9 Things We Know
(click image for larger view)
The Syrian Electronic Army: 9 Things We Know
Thousands of American businesses -- technology manufacturers, information security vendors, banks, satellite telecommunications providers and many others -- share threat intelligence with U.S. intelligence agencies, including details of secret zero-day vulnerabilities. In exchange, they receive access to classified intelligence, including early warnings on any attacks that have been detected that may target their networks or intellectual property, as well as where the attacks originated.

These information-sharing arrangements between businesses -- known in government parlance as "trusted partners" -- and the National Security Agency (NSA), CIA, FBI, U.S. military and other government agencies was first reported Thursday by Bloomberg. The revelations suggest that U.S. intelligence agencies' Internet monitoring programs extend far beyond the handful of secret projects detailed by recently leaked NSA documents.

Information published last week, based on secret documents leaked by former NSA contractor Edward Snowden, detailed the existence of a program to intercept metadata -- phone numbers, call duration, approximate geographical location -- on millions of U.S. cell phone subscribers. The leaked information also detailed Prism, which is an arrangement between the NSA's Special Source Operations unit program and nine U.S. Internet companies -- including Facebook, Google, Microsoft and Yahoo -- that targets foreign voice, email and video communications.

[ More information keeps coming out on government-industry security arrangements. Read Obama Defends NSA Prism, Google Denies Back Door. ]

Another secret NSA project made public by Snowden's leaked information was Blarney, which according to the Washington Post is "an ongoing collection program that leverages IC [intelligence community] and commercial partnerships to gain access and exploit foreign intelligence obtained from global networks" by targeting network backbones. Blarney collects metadata for computers being used to send emails or browse the Internet. The collected metadata includes the device's operating system, the browser being used as well as Java software version. Using that information would provide an intelligence agency with a shortcut to infiltrating any of those systems, for example by targeting known vulnerabilities in the browser or Java client.

Some of the shared information reportedly includes zero-day vulnerability details. Microsoft, for example, reportedly participates in the trusted-partner program, and shares information of vulnerabilities in its products with the government, before releasing those details -- or related fixes -- to business partners or the public. Such information could be used not only to proactively secure government computers against attack, but also to infiltrate foreign systems.

But two government officials, speaking anonymously to Bloomberg, said that while Microsoft is aware that the information it divulges can be used to target its foreign customers, legally speaking it's not allowed to ask -- and can't be told -- how the government might us this information. A Microsoft spokesman didn't immediately respond to an emailed request for comment about the full extent of its vulnerability-information-sharing arrangements with the U.S. government.

The Microsoft Active Protections Program (MAPP) counts a number of businesses and government organizations as participants, and gives them early information on vulnerabilities, in part to allow security firms to offer virtual patches against the bugs prior to their being detailed publicly. But the alleged information sharing between Microsoft and intelligence agencies would occur prior to bug information being distributed via MAPP.

The information-sharing news casts new light on how the U.S. government might have obtained the four zero-day vulnerabilities that were targeted by Stuxnet, which anonymous U.S. government officials said was a joint U.S.-Israeli project. Security researchers have said that the Stuxnet code base is quite similar to Flame and Duqu malware, suggesting that they were also the product of a U.S.-commissioned cyber weapons factory.

One critical, legal point is that unlike some U.S. government interception programs -- such as Prism -- trusted partners aren't necessarily at the receiving end of a court order or National Security Letter, which can legally not only force their participation but also silence. Instead, the trusted partner program appears to be voluntary, and includes manufacturers providing detailed information about their hardware and software to the U.S government, although they appear to be sharing no customer information.

Likewise, many telecommunications companies reportedly give U.S. intelligence agencies direct access to their offshore data centers and other facilities, which is both legal and which exempts any resulting information intercepts from oversight under the Foreign Intelligence Surveillance Act.

The former director of the NSA and CIA, Michael Hayden, told Bloomberg that this information sharing would be invaluable. "If I were the director and had a relationship with a company who was doing things that were not just directed by law but were also valuable to the defense of the Republic, I would go out of my way to thank them and give them a sense as to why this is necessary and useful," he said.

To create these types of relationships, intelligence agencies reportedly first approach one key executive, who then handpicks a few trusted IT administrators to help. "You would keep it closely held within the company and there would be very few cleared individuals," Hayden said. Businesses sometimes also request immunity from any civil suits that might result from their information sharing.

Government officials told Bloomberg that Google co-founder Sergey Brin received a temporary clearance so that he could be briefed on what came to be known as the Operation Aurora advanced persistent threat (APT) attacks against Google. The attacks were reportedly traced to a Chinese People's Liberation Army cyber-attack unit that specialized in launching APT attacks. Based on the documents leaked by Snowden, at that point, Google would have been part of the Prism program for more than a year.

Google CEO Larry Page last week said in a statement that he'd never heard of Prism, denied giving the U.S. government direct access to any Google servers and said the company only shared data with governments "only in accordance with the law."

A Google spokesman didn't immediately respond to a request for comment about Google's information-sharing arrangements with the U.S. government.

But in the face of a potential backlash from domestic and overseas customers, Google, Facebook, Microsoft and Twitter have recently petitioned the Department of Justice and FBI, requesting that they be allowed to publicly detail the ways in which they share information with the U.S. government.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2009-5142
Published: 2014-08-21
Cross-site scripting (XSS) vulnerability in timthumb.php in TimThumb 1.09 and earlier, as used in Mimbo Pro 2.3.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the src parameter.

CVE-2010-5302
Published: 2014-08-21
Cross-site scripting (XSS) vulnerability in timthumb.php in TimThumb before 1.15 as of 20100908 (r88), as used in multiple products, allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING.

CVE-2010-5303
Published: 2014-08-21
Cross-site scripting (XSS) vulnerability in the displayError function in timthumb.php in TimThumb before 1.15 (r85), as used in multiple products, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to $errorString.

CVE-2014-3562
Published: 2014-08-21
Red Hat Directory Server 8 and 389 Directory Server, when debugging is enabled, allows remote attackers to obtain sensitive replicated metadata by searching the directory.

CVE-2014-3577
Published: 2014-08-21
org.apache.http.conn.ssl.AbstractVerifier in Apache HttpComponents HttpClient before 4.3.5 and HttpAsyncClient before 4.0.2 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Three interviews on critical embedded systems and security, recorded at Black Hat 2014 in Las Vegas.