Vulnerabilities / Threats
10/6/2010
08:53 PM
50%
50%

Critical Infrastructure Providers Face Politically Motivated Attacks

A Symantec survey finds that half of critical infrastructure providers have experienced politically motivated attacks against their networks.

Strategic Security Survey: Global Threat, Local Pain
Strategic Security Survey: Global Threat, Local Pain
(click image for larger view and for full photo gallery)
More than half of critical infrastructure providers have experienced politically motivated attacks against their networks. That finding comes from a new survey of 1,580 private businesses in critical infrastructure industries -- defined as industries whose disruption could threaten national security -- conducted by Applied Research for Symantec.

In terms of attack frequency and financial fallout, critical infrastructure respondents said they had experienced a politically motivated attack 10 times in the past five years, resulting in about $850,000 in damages in total. Furthermore, 48% expect more of these attacks in the next year, while 80% expect the frequency of such attacks to increase.

"These numbers are perceptions -- we wanted to get their impressions about what they thought about government protection programs, their awareness and their readiness," said Mark Bregman, chief technology officer at Symantec.

But how do you define an attack as being politically motivated? "Usually, they're stealing something besides money -- often it's intellectual property, to further the competitiveness of a country, or to get into the critical infrastructure to get pre-positioned in case they later want to be ready to disrupt that infrastructure," said Bregman. Other activities may simply focus on gathering intelligence or understanding the nuances of a particular country's critical infrastructure networks.

In terms of network defenses, the energy industry thinks that it is best-prepared to defend against such attacks, while the communications industry is the least prepared. Even so, only one-third of providers feel "extremely prepared" to defend against all types of attacks, and 31% said they were "less than somewhat prepared."

Overwhelmingly, small organizations said they're ill prepared, although perhaps the upside is that they now know it. "It's only recently that small companies realize they're a target as much as big companies," said Bregman.

Interestingly, 90% of respondents reported that they've worked with a government critical infrastructure protection program, and half said they were quite involved. Two-thirds also said that they're willing to work with the government on security issues, and about the same number even view such collaborations favorably.

Such attitudes represent a marked shift from the early days of the government-promulgated critical infrastructure protection committees meant to coordinate security with private industry. Some of that change is due to Stuxnet, which almost overnight made information security a hot-button issue for critical infrastructure providers.

In addition, said Bregman, "in the U.S., the administration has been very outgoing and vocal about the importance of critical infrastructure and protecting it against cyber-attack," especially by appointing Howard Schmidt as cybersecurity coordinator, as well as through multiple speeches by President Obama and others in his administration.

Finally, rather than dictating from on high, the government is carving out a niche as a clearinghouse for useful -- and sometimes difficult to find -- security information and industry best practices. "These programs are not programs in which the government is providing the solution," said Bregman.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: I decided to treat the kiddos to a TV dinner tonight.
Current Issue
Five Emerging Security Threats - And What You Can Learn From Them
At Black Hat USA, researchers unveiled some nasty vulnerabilities. Is your organization ready?
Flash Poll
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
Cybercrime has become a well-organized business, complete with job specialization, funding, and online customer service. Dark Reading editors speak to cybercrime experts on the evolution of the cybercrime economy and the nature of today's attackers.