Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

5/10/2013
12:04 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

The Dragon In The Room

China, China, China

Everybody's talking China now. The federal government isn't mincing words anymore, either. No more worst-kept secret that Chinese cyberespionage is rampant, but you just can't really come out and say it. The Defense Department flat-out declared this week in a report to Congress that the Chinese government and military are attacking U.S. government networks. Then a bipartisan group of high-profile senators drafted legislation that would create a watch list of nations conducting cyberespionage against the U.S. and call out foreign firms that benefit from intellectual property stolen from the U.S.

Here's the last paragraph of the press release for the bill, called the Deter Cyber Theft Act: "Recent reports indicate that China is by far the largest source of theft attempts against U.S. companies."

The new trend of officially calling out China's cyberespionage machine actually started this past fall when the House Intelligence Committee warned U.S. companies to steer clear of doing business with Chinese telecommunications companies Huawei and ZTE due to their potential ties to the Chinese government and its spying activities. Then came Mandiant's big report on a long-suspected Chinese military link to cyberespionage against U.S. firms.

It's now OK to talk about the elephant -- er, dragon -- in the room.

"The first step toward recovery is to acknowledge our problem," quips Stewart Baker, partner in the Washington office of Steptoe & Johnson LLP and a former Department of Homeland security official. Baker says the U.S. is in "an attribution revolution" period. The intelligence community has known for more than a decade of China's activities, he says, but just hasn't spoken up like the security community has been doing.

"We know a lot about these attackers. We know what their girlfriends look like. It's not as hard as what we thought four years ago," he says. "It's embarrassing for the government because they've known this stuff for 10 to 15 years."

The "reason the debate changed," he added, is because of what security researchers at Mandiant, Trend Labs, and Citizen Labs have done, he says. "They are the only ones who have really given us the goods on the attackers. Frankly, it's a blow to the intell community that they couldn't figure out how to say things people without a security clearance could say," Baker says.

It's unlikely that the bipartisan Deter Cyber Theft Act bill, co-sponsored by Sens. Carl Levin, D-Mich.; John McCain, R-Ariz.; Jay Rockefeller, D-W.Va.; and Tom Coburn, R-Okla., is going anywhere anytime soon, though. Cybersecurity legislation -- well, practically any legislation for that matter -- has fallen flat in Congress lately. Attorney Kristen Verderame says the fact that the sponsors didn't pull in other stakeholders and committees for the bill indicates it was a more symbolic than serious legislative effort. They were basically making a statement, she says.

And for now, making a statement -- or lots of statements -- is at least a way to keep the conversation going. The trouble is that even if the average American is now at least familiar with the idea of Chinese hackers stealing U.S. trade secrets, the full economic impact of IP theft out of China has neither been truly been felt by him or her nor calculated in such a way to illustrate it.

Once that becomes clearer and its impact directly tied to American jobs and the economy, we'll need a lot more than new legislation. Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
10 Ways to Keep a Rogue RasPi From Wrecking Your Network
Curtis Franklin Jr., Senior Editor at Dark Reading,  7/10/2019
The Security of Cloud Applications
Hillel Solow, CTO and Co-founder, Protego,  7/11/2019
Where Businesses Waste Endpoint Security Budgets
Kelly Sheridan, Staff Editor, Dark Reading,  7/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-13611
PUBLISHED: 2019-07-16
An issue was discovered in python-engineio through 3.8.2. There is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability that allows attackers to make WebSocket connections to a server by using a victim's credentials, because the Origin header is not restricted.
CVE-2019-0234
PUBLISHED: 2019-07-15
A Reflected Cross-site Scripting (XSS) vulnerability exists in Apache Roller. Roller's Math Comment Authenticator did not property sanitize user input and could be exploited to perform Reflected Cross Site Scripting (XSS). The mitigation for this vulnerability is to upgrade to the latest version of ...
CVE-2018-7838
PUBLISHED: 2019-07-15
A CWE-119 Buffer Errors vulnerability exists in Modicon M580 CPU - BMEP582040, all versions before V2.90, and Modicon Ethernet Module BMENOC0301, all versions before V2.16, which could cause denial of service on the FTP service of the controller or the Ethernet BMENOC module when it receives a FTP C...
CVE-2019-6822
PUBLISHED: 2019-07-15
A Use After Free: CWE-416 vulnerability exists in Zelio Soft 2, V5.2 and earlier, which could cause remote code execution when opening a specially crafted Zelio Soft 2 project file.
CVE-2019-6823
PUBLISHED: 2019-07-15
A CWE-94: Code Injection vulnerability exists in ProClima (all versions prior to version 8.0.0) which could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system in all versions of ProClima prior to version 8.0.0.