Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

10:30 AM
Michael McMahon
Michael McMahon
Connect Directly
E-Mail vvv

Cyber Threat Analysis: A Call for Clarity

The general public deserves less hyperbole and more straight talk

I must admit that I’ve grown increasingly weary over the constant harangue in the popular press about the ever-increasing volume and severity of “cyber attacks” worldwide. The apocalyptic language, the fear mongering, and the dearth of clear and simple explanatory language obscures an already complex topic. The general public deserves less hyperbole and more straight talk.

Don’t get me wrong. I’m not downplaying the threats we are facing. Advanced persistent threat actors are homesteading on sensitive federal agency and corporate networks. Cyber threats to industrial control systems (ICS) threaten to hold critical facilities and economic sectors at risk. Denial-of-service attacks, financial compromises, and intellectual property theft disrupt our economy and sow distrust in our banking and commercial sectors.

As analysts, we must better frame this public discussion. We can start by doing what we do best – defining and explaining the nature of the problem we confront. Commentators often lump together a wide range of malicious network activity as “attacks,” disregarding the fact that we can distinguish activity by type, intent, and degree. These differentiations matter; they speak to the nature and intent of the threat actors, which ultimately is what we should be most concerned about.

Espionage & Attack
Traditionally, we differentiate between espionage and attack, and we should do the same with network activity. When the Justice Department indicts a Robert Hanssen, or arrests a group of Russian “illegals” living in the United States, we do not characterize their espionage as “attacks.” Nor should we label the reported intrusions into the White House and State Department networks as “attacks,” lest we conjure up images of combat and destruction that are inappropriate to the event. Perhaps labeling every cyber incident as an “attack” advances some political or corporate purposes. As analysts with a professional commitment to critical thinking, we must play stronger roles in structuring this conversation in ways that advance our collective understanding.

Real network attack modifies the function of a network or a physical system that the network controls. We now witness first-generation network attack capabilities taking the field: industrial control system attacks in Iran (2010) and Germany (2014); and corporate network attacks in Saudi Arabia and Qatar (2012), South Korea (2013) and the United States (2014). Federal agencies and security firms continue to identify industrial control attack tools (some of which had gone unrecognized for years) that may reside on any number of sensitive control systems worldwide. Global proliferation of increasingly destructive network attack capabilities warrants serious attention and should be properly differentiated from espionage.

A Chinese hacker stealing intellectual property from a US defense contractor is qualitatively different from a BlackEnergy implant in a natural gas pipeline control system. Both are malicious activities, but differ substantially in intent and degree of potential impact.

Sometimes clear differentiation eludes us. Espionage and attack often employ similar means of ingress, exploitation, and persistent presence. Some operations—such as the Sony Pictures Entertainment hack—combined elements of both. These challenges should compel us to explore new ways to clearly identify and characterize cyber threats.

A way forward
As analysts with a dedication to tradecraft, we must seek out approaches that better differentiate malicious activity by type and intent. We must move the conversation past malware and digital forensics, which surely play a vital role in cyber intelligence but often offer limited explanatory power for key audiences. Most importantly, we must develop tradecraft that anticipates future threat environments, rather than simply describe and characterize present (or past) ones.

We should resist taking the bait that the popular press offers: to lump together all threat activities under one moniker of “attack.” Failing to offer at least some degree of activity differentiation only contributes to the malaise that strangles our general discussion on the nature of cyber threat.

Do not dismiss the general public as incapable of understanding the technical nuances of cyber threat activity. Our audiences are savvier than we give them credit for; to condescend to them or even write them off altogether is simply high-tech hubris. Even more important, popular understanding matters. An informed public discourse—the cornerstone of any democratic society—forms the basis for developing sound public policy. In our role as analysts, we owe this process the best of our tradecraft, our intellectual rigor, and simple clarity.

Michael McMahon is Director, Cyber Strategy and Analysis at Innovative Analytics & Training, LLC, a Washington, DC-based research consultancy and professional services firm. Mike is a 25-year veteran of the US intelligence community, serving most recently on the National ... View Full Bio
Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
<<   <   Page 2 / 2
Joe Stanganelli
Joe Stanganelli,
User Rank: Ninja
5/23/2015 | 11:08:10 PM
Respectful Disagreement
I disagree, respectfully.

I'm not convinced we're particularly overhyping cyber threats; I think we were *under*-hyping them for a really long time (although there have been points where they were overhyped, especially in the late '90s, when people believed that any teenager with a modem was a dangerous criminal who could do ANYTHING).  What's more, I think both private sector and public sector attitudes alike to cyber security until recently demonstrate, in their lackadaisical nature, just how under-hyped cyber threats have been.

As for calling these data breaches "attacks"...  An attack, strictly speaking, is merely an aggressive action against an entity.  I see no problem with calling things what they actually are.
User Rank: Strategist
5/22/2015 | 3:38:09 PM
Cyber COMs
Agree that we need to drive the conversation further and create tools and techniques that dig deeper. This should include technical attribution (e.g., those annoying and cheap DFIR and NSM IOCs) for current-running, active campaigns but also must include warning intelligence indicators (i.e., I&W).

We lack strategic thinkers and we fear strategic planning. The nature of cyber risk is understood by such a select few, it makes it difficult to open the conversation to both the global audience at the state level as well as at the Global 2k level. Someone just needs to drive a social science as complete as economics for information risk. We need to go way beyond what FAIR delivers to small markets today -- it needs to become heavily academic.

The cyber crime common operating picture can likely be explained using modern criminal studies theories. However, there are other moving pieces: as you mention, cyber espionage -- but I would add areas of cyber warfare and/or cyber terrorism which could include cyber sabotage and kinetic cyber.

I spoke recently on cyber common operating models, and I plan to iterate on my approach in order to make it more accessible. The model includes these four COPs: crime, espionage, sabotage, and kinetic cyber. There are other factors or variables to include and solve, but this is a purposeful simplification.

Nothing prevents TAXII (sub STIX, sub MAEC, etc) from communicating I&W indicators along with IOCs. The systems we are implementing today support the technology needs and can likely scale them. We are missing the analysts who can start writing and sharing I&W indicators. We are missing the process (N.B., it's close to standard tradecraft, though) and the governance.

The NIST CSF mentions predictive indicators. I could argue about word choice there, but we don't see a clear direction or implementation either way. I have yet to scope the problem using modern tools, but would likely start with SA-Splice for Splunk or STIXtego. I don't know enough Palantir to make something like this grow wings. Some of the research from RecordedFuture, SiloBreaker, Kapow, RiskIQ, and Packet Ninjas is moving in this direction, but it's very early stage in the game.
<<   <   Page 2 / 2
How Attackers Infiltrate the Supply Chain & What to Do About It
Shay Nahari, Head of Red-Team Services at CyberArk,  7/16/2019
US Mayors Commit to Just Saying No to Ransomware
Robert Lemos, Contributing Writer,  7/16/2019
The Problem with Proprietary Testing: NSS Labs vs. CrowdStrike
Brian Monkman, Executive Director at NetSecOPEN,  7/19/2019
Register for Dark Reading Newsletters
White Papers
Cartoon Contest
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2019-07-22
All versions up to V1.19.20.02 of ZTE OTCP product are impacted by XSS vulnerability. Due to XSS, when an attacker invokes the security management to obtain the resources of the specified operation code owned by a user, the malicious script code could be transmitted in the parameter. If the front en...
PUBLISHED: 2019-07-22
tcpdump.org tcpdump 4.9.2 is affected by: CWE-126: Buffer Over-read. The impact is: May expose Saved Frame Pointer, Return Address etc. on stack. The component is: line 234: &quot;ND_PRINT((ndo, &quot;%s&quot;, buf));&quot;, in function named &quot;print_prefix&quot;, in &quot;print-hncp.c&quot;. Th...
PUBLISHED: 2019-07-22
aubio 0.4.8 and earlier is affected by: null pointer. The impact is: crash. The component is: filterbank. The attack vector is: pass invalid arguments to new_aubio_filterbank. The fixed version is: after commit eda95c9c22b4f0b466ae94c4708765eaae6e709e.
PUBLISHED: 2019-07-22
aubio 0.4.8 and earlier is affected by: Buffer Overflow. The impact is: buffer overflow in strcpy. The component is: tempo. The fixed version is: after commit b1559f4c9ce2b304d8d27ffdc7128b6795ca82e5.
PUBLISHED: 2019-07-22
aubio 0.4.8 and earlier is affected by: null pointer. The impact is: crash (DoS). The component is: onset. The fixed version is: after commit e4e0861cffbc8d3a53dcd18f9ae85797690d67c7.